CVE-2018-25143

8.8

Microhard Systems · IPn4G and various Cellular Gateways

Multiple Microhard Systems industrial gateways contain a command injection vulnerability in a custom ping command, allowing authenticated users to escape a restricted shell and execute root commands.

Executive summary

A critical command injection vulnerability in various Microhard Systems industrial gateways allows authenticated attackers to gain full root-level control of the device.

Vulnerability

The device includes a restricted SSH service (msshc) that can be enabled by an authenticated user via the web interface or CSRF. Once connected to this service, an attacker can exploit a flawed ping command to escape the jailed environment and execute arbitrary commands with root privileges.

Business impact

Successful exploitation grants an attacker complete control over the affected industrial gateway. This could lead to the interception of sensitive operational data, unauthorized network access to connected industrial sensors or serial devices, and potential disruption of critical infrastructure services. With a CVSS score of 8.8, this vulnerability represents a high risk to operational stability and system integrity.

Remediation

Immediate Action: Contact Microhard Systems support to obtain firmware updates for your specific device model and build version. Ensure the msshc service is disabled in the web administration panel if it is not required for legitimate operational tasks.

Proactive Monitoring: Review system access logs for unauthorized SSH connections or unexpected activation of the Microhard Sh service. Monitor for anomalous traffic originating from the gateway that may indicate persistent unauthorized access.

Compensating Controls: Restrict network access to the web administration interface using firewall rules to ensure only trusted management IP addresses can reach the device. Implement strict network segmentation to minimize the impact if a device is compromised.

Exploitation status

Public Exploit Available: Yes, a local exploit is available via ExploitDB (EDB-ID 45041).

Analyst recommendation

Given the potential for root-level command execution and the availability of a public exploit, this vulnerability poses a significant threat to industrial environments. Administrators must prioritize updating affected hardware immediately and strictly enforce network access controls to prevent unauthorized access to administrative interfaces.

More Microhard Systems CVEs

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.