CVE-2018-25147
Unknown
Unknown - Not Provided
Hardcoded Credentials in Microhard IPn4G Allow Root Access
Publication date: 2025-12-24
Last updated on: 2025-12-24
Assigner: VulnCheck
Description
Description
Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microhard_systems | ipn4g | 1.1.0 |
| microhard_systems | vip4gb | * |
| microhard_systems | dragon-lte | * |
| microhard_systems | bullet-3g | * |
| microhard_systems | vip4g-wifi-n | * |
| microhard_systems | ipn3gii | * |
| microhard_systems | bullet-lte | * |
| microhard_systems | bulletplus | * |
| microhard_systems | httpd-ssl | 1.0.0 |
| microhard_systems | vip4g | * |
| microhard_systems | ipn3gb | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1392 | The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality. |