First published: Tue Oct 19 2021(Updated: )
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not contain an X-FRAME-OPTIONS header, which an attacker may take advantage of by sending a link to an administrator that frames the router’s management portal and could lure the administrator to perform changes.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Inhandnetworks Ir615 Firmware | =2.3.0.r4724 | |
Inhandnetworks Ir615 | ||
Inhandnetworks Ir615 Firmware | =2.3.0.r4870 | |
InHand Networks IR615 Router: Versions 2.3.0.r5417 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38472 is a vulnerability in InHand Networks IR615 Router's management portal that allows an attacker to frame the portal and trick administrators into performing malicious actions.
An attacker can exploit CVE-2021-38472 by sending a link to an administrator that frames the router's management portal and tricks the administrator into performing unauthorized actions.
The severity of CVE-2021-38472 is medium with a CVSS score of 4.7.
Versions 2.3.0.r4724 and 2.3.0.r4870 of InHand Networks IR615 Router are affected by CVE-2021-38472.
To mitigate CVE-2021-38472, update to a version of InHand Networks IR615 Router software that includes an X-FRAME-OPTIONS header to prevent framing attacks.