ZeroHour

CVE-2018-25144

PoC ×2
CVSS 4.0
8.7 high
EPSS
<1%p41
Published
()
Modified
Description

Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete arbitrary files. Attackers can exploit unsanitized 'path', 'savefile', 'edit', and 'delfile' parameters to perform unauthorized file system modifications through GET and POST requests.

Vendors
microhardcorp
Products
ipn4g firmware, ipn3gb firmware, ipn4gb firmware, bullet-3g firmware, vip4gb firmware, vip4gb wifi-n firmware, bullet-lte firmware, ipn3gii firmware, ipn4gii firmware, bulletplus firmware, dragon-lte firmware
Weakness
CWE-22
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.