7.1
CVE-2025-35004
- EPSS 0.17%
- Veröffentlicht 08.06.2025 21:15:31
- Zuletzt bearbeitet 12.01.2026 16:54:35
- Quelle cve@takeonme.org
- CVE-Watchlists
- Unerledigt
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFIP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microhardcorp ≫ Ipn4gii-na2 Firmware Version <= 1.2.0-r1132
Microhardcorp ≫ Bulletlte-na2 Firmware Version <= 1.2.0-r1132
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.375 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@takeonme.org | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.