Microhard Systems IPn4G Process Manipulation Vulnerability Allowing Denial-of-Service

Vulnerability

A vulnerability in Microhard Systems IPn4G version 1.1.0 has been identified, allowing authenticated attackers to exploit a hidden feature that lets them list and manipulate active system processes. This vulnerability can be used to send arbitrary signals to terminate background processes and disrupt system services, potentially causing a denial-of-service condition that requires restarting the device. The issue can also be triggered by cross-site request forgery (CSRF) attacks, with the malicious changes needing a device restart or factory reset to revert.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition by causing unintended disruptions to system processes and services, which can require a device restart or factory reset to resolve.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/cgi-bin/webif/status-processes.sh' endpoint. The request must include an 'Authorization' header with valid credentials. Once the process listing is obtained, arbitrary signals can be sent to terminate specific processes, including those related to system services.

Added: Dec 24, 2025, 8:43 PM
Updated: Dec 24, 2025, 9:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
1.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.