← back
CVE-2021-38476mediumCWE-204

InHand Networks IR615 Router

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
In short

The IR615 Router reveals whether a username exists based on how it responds during login attempts. An attacker can use this to discover valid user accounts on the device.

Technical detail

The authentication mechanism exhibits user enumeration vulnerability through differential response analysis (CWE-204). An unauthenticated attacker can probe the login endpoint to determine valid usernames by observing variations in authentication responses, facilitating targeted credential attacks.

Summary generated and translated by AI from the official description.
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and validates the existence of a username. This may allow an attacker to enumerate different user accounts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N