Microhardcorp
Microhardcorp Vip4gb Firmware: vulnerabilities and CVEs
Microhardcorp Vip4gb Firmware has 7 published vulnerabilities, 7 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months7
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25149 | Medium (5.1) | 0.22% | — | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin… |
| CVE-2018-25148 | High (8.7) | 0.78% | — | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can… |
| CVE-2018-25147 | Critical (9.3) | 0.39% | — | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to… |
| CVE-2018-25146 | High (7.1) | 0.49% | — | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes… |
| CVE-2018-25145 | High (7.1) | 0.47% | — | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from… |
| CVE-2018-25144 | High (8.7) | 0.48% | — | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete arbitrary files. Attackers can exploit… |
| CVE-2018-25143 | High (8.7) | 0.60% | — | Dec 24, 2025 | Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.