CVE-2021-38486 HIGH

CVE-2021-38486: InHand Networks IR615 Router

Vendor Inhand Networks
Product IR615 Router
Weakness CWE-285
Published October 19, 2021
Last update September 16, 2024

CVSS base score

8.0/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have full control over the product and execute code within the internal network to which the product is connected.

Key dates

02Disclosure timeline

October 19, 2021 CVE published
September 16, 2024 Record updated