« Back to list

Microhardcorp

Microhardcorp Vip4gb Firmware: vulnerabilities and CVEs

Microhardcorp Vip4gb Firmware has 7 published vulnerabilities, 7 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months7
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2018-25149Medium (5.1)0.22%—Dec 24, 2025
Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin…
CVE-2018-25148High (8.7)0.78%—Dec 24, 2025
Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can…
CVE-2018-25147Critical (9.3)0.39%—Dec 24, 2025
Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to…
CVE-2018-25146High (7.1)0.49%—Dec 24, 2025
Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes…
CVE-2018-25145High (7.1)0.47%—Dec 24, 2025
Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from…
CVE-2018-25144High (8.7)0.48%—Dec 24, 2025
Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete arbitrary files. Attackers can exploit…
CVE-2018-25143High (8.7)0.60%—Dec 24, 2025
Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services4
  2. T1005 Data from Local System2
  3. T1059 Command and Scripting Interpreter2
  4. T1078 Valid Accounts1
  5. T1190 Exploit Public-Facing Application1
  6. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microhardcorp