QID 590971

Date Published: 2022-08-05

QID 590971: InHand Networks IR615 Router (Update A) Multiple Vulnerabilities (ICSA-21-280-05)

AFFECTED PRODUCTS
The following versions of the InHand Networks IR615 Router are affected:
IR615 Router: Versions 2.3.0.r5417 and prior

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may allow an attacker to have full control over the product, remotely perform actions on the product, intercept communication and steal sensitive information, session hijacking, and successful brute-force against user passwords. Additional successful exploitation may allow for the uploading of malicious files, deletion of system files, execution of remote code, and enumeration of user accounts and passwords.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-280-05 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-280-05 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-280-05