Microhardcorp's vulnerability profile centers on a focused line of mobile broadband and cellular connectivity appliances including the Bullet LTE, Bullet 3G, and BulletPlus product families. The recurring exposure concentrates in input-handling and command-injection weakness classes—argument injection, OS command injection, and path traversal—alongside web-layer issues such as cross-site request forgery and improper access controls, typical of embedded networking devices where firmware and web interfaces share authentication and input-validation responsibilities. A meaningful share of vulnerabilities reach serious severity; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microhardcorp over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-17406HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authentication is required to exploit | Oct 13, 2020 | 8.8 | 29 | NO | NO |
CVE-2018-25148HIGH Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify sy | Dec 24, 2025 | 8.8 | 28 | NO | NO |
CVE-2018-25143HIGH Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a | Dec 24, 2025 | 8.8 | 28 | NO | NO |
CVE-2018-25144HIGH Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete a | Dec 24, 2025 | 8.4 | 27 | NO | NO |
CVE-2020-17407CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authentication is not required to expl | Oct 13, 2020 | 9.8 | 26 | NO | NO |
CVE-2018-25147HIGH Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to ga | Dec 24, 2025 | 7.5 | 25 | NO | NO |
CVE-2018-25146HIGH Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitra | Dec 24, 2025 | 8.1 | 25 | NO | NO |
CVE-2018-25149MEDIUM Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft | Dec 24, 2025 | 6.5 | 22 | NO | NO |
CVE-2018-25145MEDIUM Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers | Dec 24, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-35009HIGH Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNNETSP command that can lead to pri | Jun 8, 2025 | 7.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microhardcorp.
Media articles that mention a CVE ID that affects a product developed by Microhardcorp — matched by CVE ID, not by vendor name.