CVE-2026-38718: InHand IR912/IR915 Buffer Overflow Denial of Service
InHand Networks has released information about a buffer overflow vulnerability affecting IR912 and IR915 industrial routers (version 1.0.0.r20042 and earlier). An unauthenticated attacker on the network can send specially crafted data during device registration that overflows a memory buffer, crashing the device and rendering it unavailable. No authentication or user interaction is required to trigger the issue.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-120
- Affected products
- 4 configuration(s)
- Published / Modified
- 2026-06-18 / 2026-06-22
NVD description (verbatim)
InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a buffer overflow vulnerability in the device registration function. This vulnerability could allow an attacker to cause a denial of service attack on the remote target device.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-38718 is a classic stack or heap-based buffer overflow (CWE-120) in the device registration function of InHand industrial gateways. The vulnerability exists because the registration handler does not properly validate the length of user-supplied input before copying it into a fixed-size buffer. An attacker can craft a registration request with an oversized payload to corrupt memory, overwrite function pointers or return addresses, and crash the process. The CVSS 3.1 score of 7.5 (HIGH) reflects the high availability impact and ease of exploitation (network-accessible, no privileges required, no user interaction).
Business impact
IR912 and IR915 devices are commonly deployed as edge gateways in industrial, remote-site, and branch office environments for cellular connectivity and WAN failover. A successful denial-of-service attack via this vulnerability could interrupt critical connectivity, halt remote monitoring and control operations, and force emergency maintenance or device replacement. In mission-critical deployments (utilities, manufacturing, emergency response), even brief unavailability can have cascading operational consequences.
Affected systems
The vulnerability affects InHand Networks IR912 and IR915 devices running firmware version 1.0.0.r20042 and all earlier versions. Specifically affected models include IR912L-FQ58 and IR915L-FQ39-S. Verify your device firmware version and model against InHand's advisory to confirm exposure. Devices running patched versions after 1.0.0.r20042 are not affected.
Exploitability
Exploitability is high. The vulnerability requires no authentication, no special privileges, and no user interaction. Any attacker with network access to the device's registration interface can trigger the buffer overflow. No exploit code has been observed in the wild as of the publication date, but the simplicity of buffer overflow exploitation makes weaponization trivial. The device is designed for remote management, making it likely to be internet-facing in many deployments.
Remediation
InHand Networks has released patched firmware for both affected models. Organizations should immediately identify all IR912 and IR915 devices in their inventory, verify current firmware versions, and apply vendor patches as soon as operationally feasible. Firmware updates should be validated in a non-production environment first to ensure compatibility with existing configurations and integrations. Given the high exploitability and availability impact, patches should be prioritized for internet-facing or publicly routable devices.
Patch guidance
Obtain the latest firmware from InHand Networks' support portal or your authorized reseller. The patched version will be explicitly noted in the security advisory with a version number higher than 1.0.0.r20042. Follow InHand's documented firmware upgrade procedure, which typically involves downloading the image, backing up device configuration, and initiating a controlled reboot. Some deployments may require coordinated maintenance windows or redundancy measures. Test patches in a representative lab environment before mass deployment.
Detection guidance
Monitor device logs for registration requests with abnormally large payloads or malformed registration protocol messages that precede device crashes or reboots. Network intrusion detection systems (IDS) can flag oversized registration frames or repeated failed registration attempts. Check for unexpected device unavailability or spontaneous reboots in your IR912/IR915 fleet, which may indicate exploitation attempts. Enable syslog forwarding and centralize device event logs to establish a baseline of normal registration traffic and identify anomalies.
Why prioritize this
This vulnerability merits urgent attention despite not yet being included in CISA's Known Exploited Vulnerabilities (KEV) catalog. The combination of high CVSS score (7.5), complete absence of authentication barriers, trivial exploitability of buffer overflows, and the typical internet-facing deployment of these industrial gateways creates a compelling exploitation incentive. The availability impact aligns with disruptive attack objectives. Early patching reduces risk substantially before the vulnerability gains wider attention or is added to public exploit databases.
Risk score, explained
The CVSS 3.1 score of 7.5 reflects a network-accessible denial-of-service condition with no authentication, low complexity, and no user interaction required. The attack vector is Network (AV:N), access complexity is Low (AC:L), privileges required is None (PR:N), user interaction is None (UI:N), and scope is Unchanged (S:U). The impact is purely on availability (A:H) with no confidentiality or integrity compromise, which caps the score below critical severity. However, the accessibility and ease of exploitation elevate concern in practice.
Frequently asked questions
Is there a workaround if I cannot patch immediately?
Network segmentation is your primary control. Restrict access to the device registration interface to trusted IP ranges or VPNs only. Disable the device's external management interface if not actively required. Implement network-based rate limiting on registration attempts to reduce the window of vulnerability. However, these are temporary measures—patching remains essential.
How do I verify if my device is vulnerable?
Check the firmware version on your IR912 or IR915 by logging into the management interface or examining device information via SSH/CLI. If the version is 1.0.0.r20042 or earlier, you are vulnerable. Cross-reference your model number (IR912L-FQ58 or IR915L-FQ39-S) against InHand's official advisory to confirm applicability.
What happens if the device is exploited?
A successful exploit causes the device to crash or reboot, resulting in loss of connectivity through that gateway. Depending on your network design, this may interrupt WAN failover, cellular connectivity, or remote site access until the device is manually rebooted or automatically recovers. There is no data theft or system compromise—the impact is strictly denial of service.
Will CISA add this to the KEV catalog?
Currently, CVE-2026-38718 is not listed in CISA's Known Exploited Vulnerabilities catalog. Whether it will be added depends on evidence of active exploitation in the wild or targeting by state or criminal actors. Regardless of KEV status, the vulnerability's technical characteristics warrant prompt patching in any industrial or critical-access environment.
This analysis is provided for informational purposes to help security teams understand and prioritize vulnerability remediation. It is not a substitute for official vendor advisories, patch testing in your environment, or consultation with InHand Networks support. CVSS scores, affected versions, and patch details are sourced from published CVE data and vendor information current as of the analysis date. Always verify patch applicability and compatibility against your specific device models and firmware versions before deployment. SEC.co makes no warranty regarding the completeness or timeliness of this analysis. Source: NVD (public-domain), retrieved 2026-07-27. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2018-25426HIGHWinMTR 0.91 Denial-of-Service Buffer Overflow Vulnerability
- CVE-2018-25432HIGHArm Whois 3.11 Buffer Overflow Allows Local Code Execution
- CVE-2019-25733HIGHNetShareWatcher 1.5.8.0 SEH Buffer Overflow – Local Code Execution
- CVE-2019-25735HIGHAllPlayer 7.4 Buffer Overflow in URL Handling – Local Code Execution Risk
- CVE-2019-25736HIGHLabF nfsAxe 3.7 Buffer Overflow – Local Code Execution
- CVE-2025-26240HIGHJazzCore python-pdfkit 1.0.0 JavaScript Execution & File Exfiltration
- CVE-2026-0138HIGHAndroid LWIS Buffer Overflow Leading to Local Privilege Escalation
- CVE-2026-0146HIGHAndroid Media Codec Out-of-Bounds Write – RCE Risk