Description
Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, including starting services, disabling firewalls, and writing files to the system.
Problem types
Incorrect Privilege Assignment
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5479.php
www.exploit-db.com/exploits/45038 (ExploitDB-45038)
www.microhardcorp.com (Microhard Systems Product Web Page)
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5479.php (Zero Science Lab Disclosure (ZSL-2018-5479))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.