← Vulnerability feed

Vulnerability record · CVE-2020-17407 · published 13 October 2020

CVE-2020-17407: Microhardcorp bullet-lte firmware stack-based buffer overflow vulnerability

Microhardcorp · Bullet Lte Firmware

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of authentication headers. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-10596.

9.8 CVSS 3.1 Critical EPSS 6.8% · top 6.2% CWE-121 · Stack-based buffer overflow
9.8CVSS 3.1 base score, v2 10.0
6.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of authentication headers. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-10596.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-17407 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2018-25147Microhardcorp ipn4g firmware vulnerabilityMicrohard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit …EPSS 0.39%8.8CVE-2020-17406Microhardcorp bullet-lte firmware os command injection vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authent…EPSS 5.3%8.7CVE-2018-25148Microhardcorp ipn4g firmware vulnerabilityMicrohard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to cr…EPSS 0.78%8.7CVE-2018-25143Microhardcorp ipn4g firmware os command injection vulnerabilityMicrohard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc…EPSS 0.60%8.7CVE-2018-25144Microhardcorp ipn4g firmware path traversal vulnerabilityMicrohard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attacke…EPSS 0.48%7.1CVE-2018-25146Microhardcorp ipn4g firmware incorrect authorization vulnerabilityMicrohard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system proces…EPSS 0.49%7.1CVE-2018-25145Microhardcorp ipn4g firmware vulnerabilityMicrohard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system…EPSS 0.47%5.1CVE-2018-25149Microhardcorp ipn4g firmware cross-site request forgery vulnerabilityMicrohard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without use…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2020-17407), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.