Microhard Systems IPn4G Hardcoded Default Credentials Vulnerability

Vulnerability

A vulnerability exists in the Microhard Systems IPn4G 1.1.0 gateway due to hardcoded default credentials that cannot be changed through normal operations. This flaw allows attackers to gain unauthorized root access by logging in with predefined username and password combinations. The issue is rooted in the Linux distribution of the device, where these credentials are embedded but not exposed to the user.

Impact

Exploitation of this vulnerability allows for unauthorized root-level access to the device.

Reproduction

The vulnerability can be reproduced by logging into the device using the hardcoded default credentials. Once logged in, an authenticated attacker could potentially exploit another vulnerability to gain root access.

Added: Dec 24, 2025, 8:42 PM
Updated: Dec 24, 2025, 9:44 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
1.5
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.