CVE-2026-38703
Last modified
CVE-2026-38703 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.. EPSS estimates a 1.24% chance of exploitation in the next 30 days.
Description
A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Inhandnetworks | Ir315 Firmware | < 1.0.121 |
| Inhandnetworks | Ir302 Firmware | < 3.5.112 |
| Inhandnetworks | Ir615 Firmware | < 1.0.121 |
| Inhandnetworks | Ir305 Firmware | < 1.0.121 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-38703?
How severe is CVE-2026-38703?
How do I fix CVE-2026-38703?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-38651Authentication Bypass vulnerability exists in Netmaker versi…8.2
- CVE-2026-38669wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when …6.1
- CVE-2026-3867An improper ownership management vulnerability has been iden…6
- CVE-2026-3868An improper handling of the length parameter inconsistency v…8.7
- CVE-2026-3870A buffer overflow vulnerability in the UPnP AddPortMapping()…6.5
- CVE-2026-38702A command injection vulnerability exists in the Admin Access…9.8
- CVE-2026-38704A command injection vulnerability exists in the WireGuard VP…9.8
- CVE-2026-38707A command injection vulnerability exists in the IPSec VPN fe…9.8
- CVE-2026-38708TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.2…9.8
- CVE-2026-38709TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.2…9.8
- CVE-2026-3871A buffer overflow vulnerability in the UPnP DeletePortMappin…6.5
- CVE-2026-38710TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain…7.2
Are you affected by CVE-2026-38703?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
