CVE-2018-25147

Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.

high 7.5 CVSS 3.1
Published: Dec 24, 2025
Modified: Jan 26, 2026
Vendor: Microhardcorp
Product: Ipn4G Firmware
Versions: 1.1.0,2.2.0,1.1.6,1.2.0,1.3.0

Description

Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.

References

Related CVEs