CVE-2022-26510
https://notcve.org/view.php?id=CVE-2022-26510
12 May 2022 — A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de actualización de firmware en la funcionalidad iburn firmware checks de InHand Networks InRouter302 versión V3.5.37. Una petición HTTP especialmente diseñada puede conllevar a una actualización del firmware. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1495 • CWE-347: Improper Verification of Cryptographic Signature •
CVE-2022-26420
https://notcve.org/view.php?id=CVE-2022-26420
12 May 2022 — An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de inyección de comandos del Sistema Operativo en la funcionalidad infactory_port de la consola de InHand Networks InRouter302 versión V3.5.37. Una serie de peticiones de red especialmente diseña... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1499 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-26085
https://notcve.org/view.php?id=CVE-2022-26085
12 May 2022 — An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. Se presenta una vulnerabilidad de inyección de comandos del Sistema Operativo en la funcionalidad httpd wlscan_ASP de InHand Networks InRouter302 versión V3.5.4. Una petición HTTP especialmente diseñada puede conllevar a una ejecución... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1473 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-26075
https://notcve.org/view.php?id=CVE-2022-26075
12 May 2022 — An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de inyección de comandos del Sistema Operativo en la funcionalidad infactory_wlan de la consola de InHand Networks InRouter302 versión V3.5.37. Una serie de peticiones de red especialmente diseña... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1500 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-26042
https://notcve.org/view.php?id=CVE-2022-26042
12 May 2022 — An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de inyección de comandos del Sistema Operativo en la funcionalidad daretools binary de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllevar a una ejecución d... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1478 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-26020
https://notcve.org/view.php?id=CVE-2022-26020
12 May 2022 — An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability. Se presenta una vulnerabilidad de divulgación de información en la funcionalidad router configuration export de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllevar a un aumento de privileg... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1474 • CWE-321: Use of Hard-coded Cryptographic Key CWE-798: Use of Hard-coded Credentials •
CVE-2022-26007
https://notcve.org/view.php?id=CVE-2022-26007
12 May 2022 — An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de inyección de comandos del Sistema Operativo en la funcionalidad console factory de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllevar a una ejecución de un comando... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1475 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-26002
https://notcve.org/view.php?id=CVE-2022-26002
12 May 2022 — A stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of malicious packets to trigger this vulnerability. Se presenta una vulnerabilidad de desbordamiento de búfer en la región stack de la memoria en la funcionalidad console factory de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllev... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1476 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •
CVE-2022-25995
https://notcve.org/view.php?id=CVE-2022-25995
12 May 2022 — A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de ejecución de comandos en la funcionalidad console inhand de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllevar a una ejecución de un comando arbitrario. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1477 • CWE-489: Active Debug Code •
CVE-2022-25172
https://notcve.org/view.php?id=CVE-2022-25172
12 May 2022 — An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie. Se presenta una vulnerabilidad de divulgación de información en la funcionalidad web interface session cookie de InHand Networks InRouter302 versión V3.5.4. La cookie de sesión carece del flag HttpOnly, h... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1470 • CWE-732: Incorrect Permission Assignment for Critical Resource CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag •