Microhard BulletLTE-NA2 and IPn4Gii-NA2 Post-Authentication Command Injection Vulnerability

Vulnerability

A post-authentication command injection vulnerability has been identified in the Microhard BulletLTE-NA2 and IPn4Gii-NA2 products. This vulnerability resides within the AT+MFMAC command of the restricted command-line interface (CLI) and can lead to privilege escalation. The issue allows authenticated users to inject commands that are executed with root privileges, thereby escaping the restricted shell and gaining full access to the device.

Impact

Exploitation of this vulnerability allows authenticated users to perform command injection via the AT+MFMAC command, executing arbitrary commands as the root user. This could lead to unauthorized access and control over the device.

Reproduction

To reproduce this vulnerability, an authenticated user must access the device's CLI via telnet or SSH. Once connected, the user can issue the AT+MFMAC command. By injecting commands wrapped in backticks or dollar-parentheses, and using the internal field separator for space-delimited arguments, it is possible to execute arbitrary commands as the root user. For example, injecting a command to open a reverse shell would demonstrate the exploitation of this vulnerability.

Added: Jun 8, 2025, 9:24 PM
Updated: Jun 8, 2025, 9:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
6.2
remediation
0.0
relevance
0.1
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.