Microhard Systems IPn4G Authentication Bypass Vulnerability Allowing Arbitrary File Access and Modification

Vulnerability

An authentication bypass vulnerability has been identified in Microhard Systems IPn4G version 1.1.0. The issue resides in a hidden script called 'system-editor.sh', which is part of the web interface. This vulnerability allows authenticated attackers to bypass authentication and gain unauthorized access to the file system. Exploitation involves manipulating unsanitized 'path', 'savefile', 'edit', and 'delfile' parameters through GET and POST requests, enabling attackers to read, modify, or delete arbitrary files on the device.

Impact

Exploitation of this vulnerability could lead to unauthorized file access and manipulation, including the potential for privilege escalation by modifying system files or user credentials.

Reproduction

The vulnerability can be reproduced by sending a GET or POST request to the 'system-editor.sh' script with the 'path' parameter set to a directory containing files to be accessed or modified. The 'savefile', 'edit', and 'delfile' parameters can be used to specify files for reading, editing, or deletion. The absence of proper input sanitization allows for arbitrary file operations to be performed.

Added: Dec 24, 2025, 8:45 PM
Updated: Dec 24, 2025, 9:47 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
1.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.