CVE-2021-38462
9.8 CRITICALInHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy
Published: 2021-10-19 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 9.8 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-521
Affected products
| Vendor | Product |
|---|---|
| inhandnetworks | ir615_firmware |
Description
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other application users and perform operations on their behalf.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2026-38707 — A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR... (9.8 CRITICAL)
- CVE-2026-38704 — A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118... (9.8 CRITICAL)
- CVE-2026-38703 — A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118,... (9.8 CRITICAL)
- CVE-2026-38702 — A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118,... (9.8 CRITICAL)
- CVE-2021-38486 — InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product wit... (8.0 HIGH)
Same CWE
- CVE-2026-11493 — A weakness has been identified in Tenda AC15 15.03.05.19 (5.0 MEDIUM)
- CVE-2024-40684 — IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3... (5.9 MEDIUM)
- CVE-2026-9394 — A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426 (3.1 LOW)
- CVE-2021-41296 — ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain fu... (9.8 CRITICAL)
- CVE-2017-7903 — A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 176... (9.8 CRITICAL)