Description
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNNETSP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17399 | Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNNETSP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing. |
References
History
Mon, 12 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microhardcorp
Microhardcorp bulletlte-na2 Microhardcorp bulletlte-na2 Firmware Microhardcorp ipn4gii-na2 Microhardcorp ipn4gii-na2 Firmware |
|
| CPEs | cpe:2.3:h:microhardcorp:bulletlte-na2:-:*:*:*:*:*:*:* cpe:2.3:h:microhardcorp:ipn4gii-na2:-:*:*:*:*:*:*:* cpe:2.3:o:microhardcorp:bulletlte-na2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:microhardcorp:ipn4gii-na2_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microhardcorp
Microhardcorp bulletlte-na2 Microhardcorp bulletlte-na2 Firmware Microhardcorp ipn4gii-na2 Microhardcorp ipn4gii-na2 Firmware |
Mon, 09 Jun 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 08 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNNETSP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing. | |
| Title | Microhard Bullet-LTE and IPn4Gii AT+MNNETSP Argument Injection | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AHA
Published:
Updated: 2025-06-09T03:17:10.831Z
Reserved: 2025-04-15T20:40:30.572Z
Link: CVE-2025-35009
Updated: 2025-06-09T03:17:07.636Z
Status : Analyzed
Published: 2025-06-08T21:15:32.500
Modified: 2026-01-12T16:55:01.207
Link: CVE-2025-35009
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD