CVE-2026-38716: Inhandnetworks IR912L-FQ58 Firmware

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

Affected products

  • Inhandnetworks IR912L-FQ58 Firmware: before 1.0.0.r20044 (fixed in 1.0.0.r20044)
  • Inhandnetworks IR915L-FQ39-S Firmware: before 1.0.0.r20044 (fixed in 1.0.0.r20044)

Published 2026-06-18. Last modified 2026-06-22.