Description
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNPINGTM command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17398 | Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNPINGTM command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing. |
References
History
Mon, 12 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microhardcorp
Microhardcorp bulletlte-na2 Microhardcorp bulletlte-na2 Firmware Microhardcorp ipn4gii-na2 Microhardcorp ipn4gii-na2 Firmware |
|
| CPEs | cpe:2.3:h:microhardcorp:bulletlte-na2:-:*:*:*:*:*:*:* cpe:2.3:h:microhardcorp:ipn4gii-na2:-:*:*:*:*:*:*:* cpe:2.3:o:microhardcorp:bulletlte-na2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:microhardcorp:ipn4gii-na2_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microhardcorp
Microhardcorp bulletlte-na2 Microhardcorp bulletlte-na2 Firmware Microhardcorp ipn4gii-na2 Microhardcorp ipn4gii-na2 Firmware |
Mon, 09 Jun 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 08 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNPINGTM command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing. | |
| Title | Microhard Bullet-LTE and IPn4Gii AT+MNPINGTM Argument Injection | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AHA
Published:
Updated: 2025-06-09T03:16:04.477Z
Reserved: 2025-04-15T20:40:30.572Z
Link: CVE-2025-35010
Updated: 2025-06-09T03:16:00.535Z
Status : Analyzed
Published: 2025-06-08T21:15:32.633
Modified: 2026-01-12T16:55:05.630
Link: CVE-2025-35010
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD