CVE-2023-22601
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientID parameters. An unauthorized user could calculate this parameter and use it to gather additional information about other InHand devices managed on the same cloud platform.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
- EPSS probability
- 0.15%
- CWE
- CWE-330
- Published
- 2023-01-12
- Last modified
- 2026-03-13
Affected products
- InHand Networks InRouter 302
- InHand Networks InRouter 615
Weakness type
Related vulnerabilities
- CVE-2026-27755 — SODOLA SL902-SWTGW124AS <= 200.1.20 Predictable Session ID
- CVE-2026-27637 — FreeScout's Predictable Authentication Token Enables Account Takeover
- CVE-2024-36389 — MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values
- CVE-2025-64097 — NervesHub has Insufficient Token Entropy that Allows Authentication Bypass via Brute Force
- CVE-2025-7783 — Usage of unsafe random function in form-data for choosing boundary
- CVE-2026-27515 — Binardat 10G08-0800GSM Network Switch Predictable Session Identifiers
- CVE-2022-26851 — Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivilege
- CVE-2024-1631 — agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`