VulnerabilityModified
CVE-2018-25149
Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent.
MEDIUM 5.1EPSS 0.22%
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated users into loading a specially crafted page.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.22% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- microhardcorp/ipn4g firmware · microhardcorp/ipn3gb firmware · microhardcorp/ipn4gb firmware · microhardcorp/bullet-3g firmware · microhardcorp/vip4gb firmware · microhardcorp/vip4gb wifi-n firmware · microhardcorp/bullet-lte firmware · microhardcorp/ipn3gii firmware · microhardcorp/ipn4gii firmware · microhardcorp/bulletplus firmware · microhardcorp/dragon-lte firmware
- Source
- disclosure@vulncheck.com
References
- http://www.microhardcorp.comProduct
- https://www.exploit-db.com/exploits/45034Exploit
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5478.phpExploit, Third Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5478.phpExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.