Loading HuntDB...

GHSA-9h47-6hm4-j5r2

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-319: Cleartext Transmission of Sensitive Information. They use an unsecured channel to communicate with the cloud platform by default. An unauthorized user could intercept this communication and steal sensitive information such as configuration information and MQTT credentials; this could allow MQTT command injection.

Related CVEs

Key Information

GHSA ID
GHSA-9h47-6hm4-j5r2
Published
January 13, 2023 12:30 AM
Last Modified
January 23, 2023 6:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 12, 2025 6:34 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.