Description
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFIP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17404 | Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFIP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing. |
References
History
Mon, 12 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microhardcorp
Microhardcorp bulletlte-na2 Microhardcorp bulletlte-na2 Firmware Microhardcorp ipn4gii-na2 Microhardcorp ipn4gii-na2 Firmware |
|
| CPEs | cpe:2.3:h:microhardcorp:bulletlte-na2:-:*:*:*:*:*:*:* cpe:2.3:h:microhardcorp:ipn4gii-na2:-:*:*:*:*:*:*:* cpe:2.3:o:microhardcorp:bulletlte-na2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:microhardcorp:ipn4gii-na2_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microhardcorp
Microhardcorp bulletlte-na2 Microhardcorp bulletlte-na2 Firmware Microhardcorp ipn4gii-na2 Microhardcorp ipn4gii-na2 Firmware |
Mon, 09 Jun 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 08 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFIP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing. | |
| Title | Microhard Bullet-LTE and IPn4Gii AT+MFIP Argument Injection | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AHA
Published:
Updated: 2025-06-09T03:22:14.184Z
Reserved: 2025-04-15T20:40:30.571Z
Link: CVE-2025-35004
Updated: 2025-06-09T03:22:10.475Z
Status : Analyzed
Published: 2025-06-08T21:15:31.807
Modified: 2026-01-12T16:54:35.330
Link: CVE-2025-35004
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD