Vulnerabilities (CVE)

Filtered by vendor Inhandnetworks Subscribe
Filtered by product Ir615
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-38478 1 Inhandnetworks 2 Ir615, Ir615 Firmware 2021-10-25 6.5 MEDIUM 9.1 CRITICAL
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute tool to inject commands into the device. This may allow the attacker to remotely run commands on behalf of the device.
CVE-2021-38462 1 Inhandnetworks 2 Ir615, Ir615 Firmware 2021-10-22 7.5 HIGH 9.8 CRITICAL
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other application users and perform operations on their behalf.
CVE-2021-38474 1 Inhandnetworks 2 Ir615, Ir615 Firmware 2021-10-22 5.0 MEDIUM 9.8 CRITICAL
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. This may allow an attacker to execute a brute-force password attack with no time limitation and without harming the normal operation of the user. This could allow an attacker to gain valid credentials for the product interface.
CVE-2021-38470 1 Inhandnetworks 2 Ir615, Ir615 Firmware 2021-10-22 6.5 MEDIUM 9.1 CRITICAL
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to inject commands into the device. This may allow the attacker to remotely run commands on behalf of the device.