Post-Authentication Command Injection in Microhard Products
CVE-2025-35009
7.1HIGH
What is CVE-2025-35009?
The Microhard BulletLTE-NA2 and IPn4Gii-NA2 products are susceptible to a post-authentication command injection vulnerability within the AT+MNNETSP command. This flaw allows attackers to manipulate command inputs improperly, potentially escalating their privileges on the system. With the implementation of CWE-88, which deals with the improper neutralization of argument delimiters in commands, this vulnerability poses significant risks. The issue persists without a general fix available, underscoring the importance of immediate action for mitigating potential exploitation in vulnerable environments.
Affected Version(s)
IPn4Gii / Bullet-LTE Firmware 0