CVE-2026-38703
InHand Networks · Industrial Routers (IR302, IR305, IR315, IR615)
A command injection vulnerability in the ZeroTier VPN feature of InHand Networks industrial routers allows remote attackers to gain root privileges.
Executive summary
A critical command injection vulnerability in the ZeroTier VPN feature of InHand Networks industrial routers allows remote attackers to obtain root privileges on target devices.
Vulnerability
The vulnerability is located within the ZeroTier VPN implementation in the firmware. An attacker can exploit this to perform command injection, leading to the acquisition of root privileges on the industrial router.
Business impact
With a CVSS score of 9.8, this vulnerability poses a severe threat to network security. Gaining root access allows an attacker to fully compromise the device, potentially facilitating unauthorized access to protected internal network segments connected via the VPN.
Remediation
Immediate Action: Update the firmware for affected InHand Networks routers to versions later than V3.5.108 (for IR302) or V1.0.118 (for IR305/IR315/IR615).
Proactive Monitoring: Monitor VPN logs for unusual activity or unauthorized configuration attempts within the ZeroTier feature.
Compensating Controls: Disable the ZeroTier VPN feature if it is not strictly necessary for business operations until the firmware update can be applied.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Security teams should immediately update the firmware on all InHand Networks industrial routers. If patching cannot be performed immediately, disabling the vulnerable ZeroTier feature is a recommended temporary measure to mitigate the risk.