Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privileges.
History

Mon, 05 Jan 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Microhardcorp
Microhardcorp ipn4g
Vendors & Products Microhardcorp
Microhardcorp ipn4g

Wed, 24 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
Description Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privileges.
Title Microhard Systems IPn4G 1.1.0 Backdoor Jailbreak via Microhard Sh Service
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-24T19:27:48.742Z

Updated: 2025-12-24T20:25:48.441Z

Reserved: 2025-12-24T14:28:02.435Z

Link: CVE-2018-25143

cve-icon Vulnrichment

Updated: 2025-12-24T20:12:06.697Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-24T20:15:48.590

Modified: 2025-12-29T15:58:13.147

Link: CVE-2018-25143

cve-icon Redhat

No data.