QID 590988

Date Published: 2022-08-24

QID 590988: InHand Networks InRouter302 Vulnerability (TALOS-2022-1471)

AFFECTED PRODUCTS
InHand Networks InRouter302 V3.5.4

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

A buffer overflow vulnerability exists in the httpd parse_ping_result API functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section TALOS-2022-1471 for affected packages and patching details.

    CVEs related to QID 590988

    Software Advisories
    Advisory ID Software Component Link
    TALOS-2022-1471 URL Logo talosintelligence.com/vulnerability_reports/TALOS-2022-1471