First published: Thu Jan 12 2023(Updated: )
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientID parameters. An unauthorized user could calculate this parameter and use it to gather additional information about other InHand devices managed on the same cloud platform.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Inhandnetworks Inrouter302 Firmware | <3.5.56 | |
Inhandnetworks Inrouter302 | ||
Inhandnetworks Inrouter615-s Firmware | <2.3.0.r5542 | |
Inhandnetworks Inrouter615-s | ||
InHand Networks InRouter 302: All versions prior to IR302 V3.5.56 | ||
InHand Networks InRouter 615: All versions prior to InRouter6XX-S-V2.3.0.r5542 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.