← Vulnerability feed

Vulnerability record · CVE-2018-25146 · published 24 December 2025

CVE-2018-25146: Microhardcorp ipn4g firmware incorrect authorization vulnerability

Microhardcorp · Ipn4g Firmware

Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes and system services through a hidden feature, potentially causing service disruption and requiring device restart.

7.1 CVSS 4.0 High EPSS 0.49% · top 60.5% CWE-863 · Incorrect authorization
7.1CVSS 4.0 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
4References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes and system services through a hidden feature, potentially causing service disruption and requiring device restart.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-25146 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17407Microhardcorp bullet-lte firmware stack-based buffer overflow vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authent…EPSS 6.8%9.3CVE-2018-25147Microhardcorp ipn4g firmware vulnerabilityMicrohard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit …EPSS 0.39%8.8CVE-2020-17406Microhardcorp bullet-lte firmware os command injection vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authent…EPSS 5.3%8.7CVE-2018-25148Microhardcorp ipn4g firmware vulnerabilityMicrohard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to cr…EPSS 0.78%8.7CVE-2018-25143Microhardcorp ipn4g firmware os command injection vulnerabilityMicrohard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc…EPSS 0.60%8.7CVE-2018-25144Microhardcorp ipn4g firmware path traversal vulnerabilityMicrohard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attacke…EPSS 0.48%7.1CVE-2018-25145Microhardcorp ipn4g firmware vulnerabilityMicrohard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system…EPSS 0.47%5.1CVE-2018-25149Microhardcorp ipn4g firmware cross-site request forgery vulnerabilityMicrohard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without use…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2018-25146), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.