Affected Vendors This Week
- InHand Networks: 5 CVEs (4 critical, 1 high)
- Cisco: 6 CVEs (1 critical, 2 high, 3 medium)
- Zyxel: 1 CVE (1 high)
Critical Vulnerabilities Demand Immediate Attention
This week brought a significant security event with five critical-severity vulnerabilities affecting industrial and edge routers. InHand Networks' IR912 and IR915 devices are facing a cascade of command injection flaws across multiple functions, all rated CVSS 9.8. These vulnerabilities affect V1.0.0.r20042 and earlier versions and impact:
- CVE-2026-38714: Python configuration function
- CVE-2026-38715: Log viewing function
- CVE-2026-38716: Python application export function
- CVE-2026-38717: File upload function
An unauthenticated attacker on the same network or with access to the device's web interface could exploit any of these to gain complete control. Additionally, CVE-2026-38718 (CVSS 7.5) introduces a buffer overflow in the device registration function, further expanding the attack surface on these models.
Cisco ISE and ISE-PIC users must prioritize patching CVE-2026-20181 (CVSS 9.1), which allows authenticated remote attackers to execute arbitrary OS commands. If you deploy these identity and access management platforms, treat this as urgent.
High-Severity Issues Across Multiple Vendors
Beyond the critical tier, CVE-2026-7273 affects Zyxel GS1900-48HPv2 switches through firmware 2.90(ABTQ.1)C0. A stack-based buffer overflow in the CGI program (CVSS 8.8) allows LAN-based unauthenticated attackers to trigger code execution—a particularly concerning risk in managed switch environments.
Cisco's CVE-2026-20190 (CVSS 7.5) exposes sensitive information via improper authorization in ISE and ISE-PIC, while CVE-2026-20220 (CVSS 6.3) in Crosswork Network Controller permits authenticated command execution on affected devices.
Medium-Severity and Recommended Actions
Three additional Cisco medium-severity issues round out the week: CVE-2026-20262 (file write/overwrite in SD-WAN Manager), CVE-2026-20246 (privilege escalation in Umbrella Virtual Appliance), and CVE-2026-20178 (malicious redirect in Webex App).
Recommended immediate actions:
- If you manage InHand IR912 or IR915 devices, check for patched firmware immediately and plan emergency updates.
- Audit Cisco ISE, ISE-PIC, and SD-WAN Manager deployments for exposure and apply vendor patches as released.
- Update Zyxel GS1900-48HPv2 switches beyond firmware 2.90(ABTQ.1)C0.
- Monitor RouterCVE.com for patch availability notices from these vendors.