CVE-2018-25146

moderate-risk
Published 2025-12-24

Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes and system services through a hidden feature, potentially causing service disruption and requiring device restart.

Do I need to act?

-
0.05% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.1/10 High
NETWORK / LOW complexity

Affected Products (15)

Ipn4G Firmware
Ipn3Gb Firmware
Ipn4Gb Firmware
Ipn4Gb Firmware
Ipn4Gb Firmware
Bullet-3G Firmware
Vip4Gb Firmware
Vip4Gb Firmware
Vip4Gb Wifi-N Firmware
Bullet-3G Firmware
Ipn3Gii Firmware
Ipn4Gii Firmware
Bulletplus Firmware
Dragon-Lte Firmware

Affected Vendors

46
/ 100
moderate-risk
Severity 28/34 · Critical
Exploitability 0/34 · Minimal
Exposure 18/34 · Moderate