CVE-2021-38486
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/10/2021
Last modified:
27/10/2022
Description
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have full control over the product and execute code within the internal network to which the product is connected.
Impact
Base Score 3.x
8.50
Severity 3.x
HIGH
Base Score 2.0
6.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:inhandnetworks:ir615_firmware:2.3.0.r4724:*:*:*:*:*:*:* | ||
| cpe:2.3:h:inhandnetworks:ir615:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:inhandnetworks:ir615_firmware:2.3.0.r4870:*:*:*:*:*:*:* | ||
| cpe:2.3:h:inhandnetworks:ir615:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



