CVE-2023-22597

MEDIUM

InRouter 302 < 3.5.56 & InRouter 615 < 2.3.0.r5542 - Cleartext Sensitive Data via Cloud

Title source: llm
STIX 2.1

Description

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-319: Cleartext Transmission of Sensitive Information. They use an unsecured channel to communicate with the cloud platform by default. An unauthorized user could intercept this communication and steal sensitive information such as configuration information and MQTT credentials; this could allow MQTT command injection.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-03

Scores

CVSS v3 6.5
EPSS 0.0051
EPSS Percentile 39.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (2)
inhandnetworks/inrouter302_firmware < 3.5.56
inhandnetworks/inrouter615-s_firmware < 2.3.0.r5542
Published Jan 12, 2023
Tracked Since Feb 18, 2026