CVE-2018-25148 Details
Description
Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, including starting services, disabling firewalls, and writing files to the system.
A remote code execution vulnerability has been identified in the Microhard Systems IPn4G version 1.1.0 admin interface. This vulnerability allows authenticated attackers to execute arbitrary commands with root privileges by exploiting hidden admin features. The exploitation can lead to the creation of crontab jobs, modification of system startup scripts, and execution of commands such as starting services, disabling firewalls, and writing files to the system.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5479.php | CISA-ADP | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/45038 | [email protected] | Exploit |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5479.php | [email protected] | ExploitThird Party Advisory |
| http://www.microhardcorp.com | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microhardcorp ipn4g firmware | 1.1.0 build1098 |
CPE
Remediation
| |
| microhardcorp ipn4g | All versions |
CPE
Remediation
| |
| microhardcorp ipn3gb firmware | 2.2.0 build2160 |
CPE
Remediation
| |
| microhardcorp ipn3gb | All versions |
CPE
Remediation
| |
| microhardcorp ipn4gb firmware | 1.1.6 build1184-14 1.1.0 rev2_build1090-2 1.1.0 rev2_build1086 |
CPE
Remediation
| |
| microhardcorp ipn4gb | All versions |
CPE
Remediation
| |
| microhardcorp bullet-3g firmware | 1.2.0 reva_build1032 1.2.0 build1076 |
CPE
Remediation
| |
| microhardcorp bullet-3g | All versions |
CPE
Remediation
| |
| microhardcorp vip4gb firmware | 1.1.6 build_1204 1.1.6 rev3_build1184-14 |
CPE
Remediation
| |
| microhardcorp vip4gb | All versions |
CPE
Remediation
| |
| microhardcorp vip4gb wifi-n firmware | 1.1.6 rev2_build1196 |
CPE
Remediation
| |
| microhardcorp vip4gb wifi-n | All versions |
CPE
Remediation
| |
| microhardcorp bullet-lte firmware | 1.2.0 build1078 |
CPE
Remediation
| |
| microhardcorp bullet-lte | All versions |
CPE
Remediation
| |
| microhardcorp ipn3gii firmware | 1.2.0 build1076 |
CPE
Remediation
| |
| microhardcorp ipn3gii | All versions |
CPE
Remediation
| |
| microhardcorp ipn4gii firmware | 1.2.0 build1078 |
CPE
Remediation
| |
| microhardcorp ipn4gii | All versions |
CPE
Remediation
| |
| microhardcorp bulletplus firmware | 1.3.0 build1036 |
CPE
Remediation
| |
| microhardcorp bulletplus | All versions |
CPE
Remediation
| |
| microhardcorp dragon-lte firmware | 1.1.0 build1036 |
CPE
Remediation
| |
| microhardcorp dragon-lte | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 21, 2026 | Initial Analysis | [email protected] |
| Dec 24, 2025 | CVE Modified | CISA-ADP |
| Dec 24, 2025 | New CVE Received | [email protected] |