Cross-Site Request Forgery Vulnerability in Microhard Systems IPn4G Product
CVE-2018-25149
Key Information:
- Vendor
Microhard Systems
- Vendor
- CVE Published:
- 24 December 2025
Badges
What is CVE-2018-25149?
Microhard Systems IPn4G version 1.1.0 is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability, enabling attackers to execute unauthorized administrative actions. By tricking users into visiting a maliciously crafted web page, an attacker can manipulate user sessions to change admin passwords, create new user accounts, and alter system settings without consent. This vulnerability emphasizes the need for enhanced security measures to protect authenticated sessions from CSRF attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway CSRF Vulnerabilities IPn4G 1.1.0 build 1098
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
