Affected Vendors This Week
- InHand Networks: 4 CVEs (all critical)
- ASUS: 3 CVEs
- TP-Link: 2 CVEs
- OpenWrt / DD-WRT: 1 CVE (high severity)
- Zyxel: 1 CVE (medium severity)
Critical Alert: InHand Networks Command Injection Flaws
This week brings four critical command injection vulnerabilities affecting InHand Networks industrial routers. All four issues carry a CVSS score of 9.8 and impact the same firmware versions across the IR302, IR305, IR315, and IR615 product lines (V3.5.108 and V1.0.118 respectively, and earlier versions).
The vulnerabilities span multiple VPN and administrative functions:
- CVE-2026-38702: Admin Access feature command injection
- CVE-2026-38703: ZeroTier VPN feature command injection
- CVE-2026-38704: WireGuard VPN feature command injection
- CVE-2026-38707: IPSec VPN feature command injection
These flaws allow unauthenticated attackers to execute arbitrary commands on affected devices. If your organization deploys InHand routers in remote monitoring, industrial IoT, or edge computing scenarios, immediate firmware patching is strongly recommended. Contact InHand support for available patches and plan updates as soon as possible.
OpenWrt Add-On Security Issue
CVE-2026-46368 (CVSS 8.8, high severity) affects the optional luci-app-https-dns-proxy package distributed through OpenWrt's community packages feed. While not installed by default, administrators who have deployed this DNS-over-HTTPS proxy add-on should review the vulnerability details and upgrade to patched versions beyond 2025.12.29-5.
Zyxel GS1200 Switch Authorization Flaw
CVE-2026-4795 (CVSS 6.5, medium severity) is a missing authorization vulnerability in Zyxel GS1200 switches affecting multiple firmware versions (GS1200-5v3, GS1200-8v3, and GS1200-5HPv3 through 1.00(ACPS/ACPT).2)C0). Verify your firmware versions and update when patches become available.
TP-Link and ASUS Lower-Severity Issues
TP-Link's Tapo smart home devices and TL-SG108PE switch have two reported issues: cleartext Bluetooth communication during setup (CVE-2026-34126) and stored XSS in the web management interface (CVE-2026-34127). ASUS similarly reported privilege escalation vulnerabilities in system components. While rated lower severity, these warrant monitoring for patches, particularly in environments where user segments have network access to these devices.