Microhard BulletLTE-NA2 and IPn4Gii-NA2 Post-Authentication Command Injection Vulnerability

Vulnerability

A post-authentication command injection vulnerability has been identified in the Microhard BulletLTE-NA2 and IPn4Gii-NA2 products. This vulnerability resides within the AT+MNPINGTM command, allowing for privilege escalation. The issue stems from improper handling of command arguments, enabling authenticated users to inject commands that are executed with root privileges. The vulnerability is accessible through a restricted command-line interface via telnet or SSH, after successful authentication.

Impact

Exploitation of this vulnerability allows authenticated users to inject commands that are executed as the root user, potentially leading to unauthorized access and control over the device.

Reproduction

To reproduce this vulnerability, log into the affected device via telnet using valid credentials. Once authenticated, the AT+MNPINGTM command can be issued with injected payloads that exploit the command injection flaw. The injected commands will be executed as the root user, bypassing the restrictions of the command-line interface.

Added: Jun 8, 2025, 9:20 PM
Updated: Jun 8, 2025, 9:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
6.2
remediation
7.7
relevance
0.1
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.