Post-Authentication Command Injection in Microhard Products
CVE-2025-35009
What is CVE-2025-35009?
The Microhard BulletLTE-NA2 and IPn4Gii-NA2 products are susceptible to a post-authentication command injection vulnerability within the AT+MNNETSP command. This flaw allows attackers to manipulate command inputs improperly, potentially escalating their privileges on the system. With the implementation of CWE-88, which deals with the improper neutralization of argument delimiters in commands, this vulnerability poses significant risks. The issue persists without a general fix available, underscoring the importance of immediate action for mitigating potential exploitation in vulnerable environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
IPn4Gii / Bullet-LTE Firmware 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
