CVE-2026-38717
ir915l-fq39-s firmware, ir915l-fq39-s
InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.
- CVSS
- 9.8
- EPSS
- 2.31% 81.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.19