← Volver a CVEs
CVE-2018-25143
HIGH8.8
Descripcion
Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privileges.
Detalles CVE
Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado12/24/2025
Ultima modificacion1/26/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
microhardcorp:bullet-3gmicrohardcorp:bullet-3g_firmwaremicrohardcorp:bullet-ltemicrohardcorp:bullet-lte_firmwaremicrohardcorp:bulletplusmicrohardcorp:bulletplus_firmwaremicrohardcorp:dragon-ltemicrohardcorp:dragon-lte_firmwaremicrohardcorp:ipn3gbmicrohardcorp:ipn3gb_firmwaremicrohardcorp:ipn3giimicrohardcorp:ipn3gii_firmwaremicrohardcorp:ipn4gmicrohardcorp:ipn4g_firmwaremicrohardcorp:ipn4gbmicrohardcorp:ipn4gb_firmwaremicrohardcorp:ipn4giimicrohardcorp:ipn4gii_firmwaremicrohardcorp:vip4gbmicrohardcorp:vip4gb_firmwaremicrohardcorp:vip4gb_wifi-nmicrohardcorp:vip4gb_wifi-n_firmware
Debilidades (CWE)
CWE-78
Referencias
http://www.microhardcorp.com(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/45041(disclosure@vulncheck.com)
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5486.php(disclosure@vulncheck.com)
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5486.php(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.