Microhard BulletLTE-NA2
cpe:2.3:h:microhardcorp:bullet-lte:*:*:*:*:*:*:*, +1 more
- <v1.2.0-r1132
A post-authentication command injection vulnerability has been identified in the Microhard BulletLTE-NA2 and IPn4Gii-NA2 products. This vulnerability resides within the AT+MNNETSP command of the restricted command-line interface (CLI) and can lead to privilege escalation. The issue allows authenticated users to inject commands that are executed with root privileges, thereby escaping the restricted shell and gaining full access to the device.
Exploitation of this vulnerability allows authenticated users to execute arbitrary commands as the root user, potentially leading to complete control over the affected device.
To reproduce this vulnerability, an authenticated user must access the device's CLI via telnet or SSH. Once logged in, the user can issue the AT+MNNETSP command, injecting malicious payloads that exploit the command injection flaw. The injected commands will be executed as the root user, allowing for unauthorized access or control over the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.