TROYANOSYVIRUS
Back to CVEs

CVE-2018-25143

HIGH
8.8

Description

Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privileges.

CVE Details

CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published12/24/2025
Last Modified1/26/2026
Sourcenvd
Honeypot Sightings0

Affected Products

microhardcorp:bullet-3gmicrohardcorp:bullet-3g_firmwaremicrohardcorp:bullet-ltemicrohardcorp:bullet-lte_firmwaremicrohardcorp:bulletplusmicrohardcorp:bulletplus_firmwaremicrohardcorp:dragon-ltemicrohardcorp:dragon-lte_firmwaremicrohardcorp:ipn3gbmicrohardcorp:ipn3gb_firmwaremicrohardcorp:ipn3giimicrohardcorp:ipn3gii_firmwaremicrohardcorp:ipn4gmicrohardcorp:ipn4g_firmwaremicrohardcorp:ipn4gbmicrohardcorp:ipn4gb_firmwaremicrohardcorp:ipn4giimicrohardcorp:ipn4gii_firmwaremicrohardcorp:vip4gbmicrohardcorp:vip4gb_firmwaremicrohardcorp:vip4gb_wifi-nmicrohardcorp:vip4gb_wifi-n_firmware

Weaknesses (CWE)

CWE-78

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.