PT-2021-22155 · Inhand Networks · Inhand Networks Ir615 Router

Published

2021-10-19

·

Updated

2021-10-22

·

CVE-2021-38480

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InHand Networks IR615 Router versions 2.3.0.r4724 through 2.3.0.r4870
Description The issue allows an attacker to perform cross-site request forgery when unauthorized commands are submitted from a trusted user, enabling remote actions on the router's management portal. This includes making configuration changes, changing administrator credentials, and running system commands on the router.
Recommendations For versions 2.3.0.r4724 and 2.3.0.r4870, as a temporary workaround, consider restricting access to the management portal to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38480

Affected Products

Inhand Networks Ir615 Router