CVE-2018-25148
Last modified
CVE-2018-25148 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, including starting services, disabling firewalls, and writing files to the system.. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, including starting services, disabling firewalls, and writing files to the system.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microhardcorp | Ipn4g Firmware | 1.1.0 | Build1098 |
| Microhardcorp | Ipn3gb Firmware | 2.2.0 | Build2160 |
| Microhardcorp | Ipn4gb Firmware | 1.1.6 | Build1184-14 |
| Microhardcorp | Ipn4gb Firmware | 1.1.0 | Rev2 Build1090-2 |
| Microhardcorp | Bullet-3g Firmware | 1.2.0 | Reva Build1032 |
| Microhardcorp | Vip4gb Firmware | 1.1.6 | Build 1204 |
| Microhardcorp | Vip4gb Wifi-N Firmware | 1.1.6 | Rev2 Build1196 |
| Microhardcorp | Bullet-Lte Firmware | 1.2.0 | Build1078 |
| Microhardcorp | Ipn3gii Firmware | 1.2.0 | Build1076 |
| Microhardcorp | Ipn4gii Firmware | 1.2.0 | Build1078 |
| Microhardcorp | Bulletplus Firmware | 1.3.0 | Build1036 |
| Microhardcorp | Dragon-Lte Firmware | 1.1.0 | Build1036 |
References
- http://www.microhardcorp.comProduct
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5479.phpExploit, Third Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5479.phpExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2018-25148?
How severe is CVE-2018-25148?
How do I fix CVE-2018-25148?
Are you affected by CVE-2018-25148?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
