5.1

CVSS4.0

CVE-2018-25149 - Microhard Systems IPn4G 1.1.0 Cross-Site Request Forgery via Web Interface

Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated userโ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

8.7

CVSS4.0

CVE-2018-25148 - Microhard Systems IPn4G 1.1.0 Remote Code Execution via Admin Interface

Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, iโ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

9.3

CVSS4.0

CVE-2018-25147 - Microhard Systems IPn4G 1.1.0 Default Credentials Authentication Bypass

Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.

๐Ÿ“… Published: Dec. 24, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

7.1

CVSS4.0

CVE-2018-25146 - Microhard Systems IPn4G 1.1.0 Service Control Denial of Service

Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes and system services through a hidden feature, potentially causing service disruโ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

7.1

CVSS4.0

CVE-2018-25145 - Microhard Systems IPn4G 1.1.0 Configuration Disclosure via Authenticated Download

Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from multiple directories including '/www', '/etc/m_cli/', and '/tmp' to access systeโ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

8.7

CVSS4.0

CVE-2018-25144 - Microhard Systems IPn4G 1.1.0 Arbitrary File Access via Undocumented System Editor

Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete arbitrary files. Attackers can exploit unsanitized 'path', 'savefile', 'edit', and 'delfile' parameters to perform unautโ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

8.7

CVSS4.0

CVE-2018-25143 - Microhard Systems IPn4G 1.1.0 Backdoor Jailbreak via Microhard Sh Service

Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privilegeโ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

7.1

CVSS4.0

CVE-2018-25142 - NovaRad NovaPACS Diagnostics Viewer 8.5 XML External Entity Injection

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

๐Ÿ“… Published: Dec. 24, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

8.7

CVSS4.0

CVE-2018-25141 - FLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated RTSP Stream Disclosure

FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming URLs without authentโ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

9.3

CVSS4.0

CVE-2018-25140 - FLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated Websocket Device Manipulation

FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initโ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.
Total resulsts: 324368
Page 8 of 32,437
ยซ previous page ยป next page
Filters