CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Inhandnetworks 2Inrouter302 Firmware Inrouter615 S FirmwareNov 21, 2024 Jan 12, 2023 N/A· v4 8.6 HIGH· v3 N/A· v2 InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly rando...Show more |
1Inhandnetworks 2Inrouter302 Firmware Inrouter615 S FirmwareNov 21, 2024 Jan 12, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-284: Improper Access Control. They allow unauthenticated devices to...Show more |
1Inhandnetworks 2Inrouter302 Firmware Inrouter615 S FirmwareNov 21, 2024 Jan 12, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-760: Use of a One-way Hash with a Predictable Salt. They send MQTT...Show more |
1Inhandnetworks 2Inrouter302 Firmware Inrouter615 S FirmwareNov 21, 2024 Jan 12, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-78: Improper Neutralization of Special Elements used in an OS Comma...Show more |
1Inhandnetworks 2Inrouter302 Firmware Inrouter615 S FirmwareNov 21, 2024 Jan 12, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-319: Cleartext Transmission of Sensitive Information. They use an un...Show more |
1Inhandnetworks 1Inrouter302 Firmware Nov 21, 2024 Nov 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an informati...Show more |
1Inhandnetworks 1Inrouter302 Firmware Nov 21, 2024 May 12, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file t...Show more |
1Inhandnetworks 1Inrouter302 Firmware Nov 21, 2024 May 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an...Show more |
1Inhandnetworks 1Inrouter302 Firmware Nov 21, 2024 May 12, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send...Show more |