CVE-2018-25147
7.5Microhard Systems · Multiple Cellular Ethernet and Serial Gateways
Multiple Microhard Systems gateway devices contain hardcoded default credentials that cannot be changed, allowing unauthenticated attackers to gain root-level access to the affected hardware.
Executive summary
Multiple Microhard Systems industrial gateways are vulnerable to unauthorized root-level access due to immutable, hardcoded default credentials.
Vulnerability
The affected devices utilize hardcoded credentials within their Linux distribution image that cannot be altered through standard administrative operations. An unauthenticated attacker can exploit this by logging into the device with these known, predefined credentials to establish full root-level control.
Business impact
Successful exploitation of this vulnerability grants an attacker full root access to industrial gateway devices. This compromise can lead to complete loss of confidentiality, integrity, and availability of the device, potentially allowing an attacker to intercept critical industrial data, modify network traffic, or pivot into restricted segments of the operational technology network. With a CVSS score of 7.5, this high-severity flaw represents a significant risk to operational continuity and system security.
Remediation
Immediate Action: Contact Microhard Systems support to obtain firmware updates that remove or allow for the modification of these hardcoded credentials. If updates are unavailable, remove these devices from internet-facing networks immediately.
Proactive Monitoring: Review device access logs for successful logins originating from unknown or unauthorized IP addresses. Monitor for unusual configuration changes or unauthorized service modifications on the gateways.
Compensating Controls: Deploy a hardware or software firewall to restrict access to the management interfaces of these gateways to trusted, internal IP addresses only. Implement strict network segmentation to ensure these devices are isolated from critical business systems.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the ExploitDB entry 45040.
Analyst recommendation
The presence of immutable hardcoded credentials in industrial hardware is a critical security deficiency that poses a severe risk to infrastructure. Administrators must prioritize the isolation of these devices from all external networks and coordinate with the vendor to implement secure authentication mechanisms. Failure to address this vulnerability leaves the affected gateways open to complete unauthorized control by external actors.
More Microhard Systems CVEs
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- ExploitDB-45040 Exploit / PoC
- Microhard Systems Product Homepage
- Zero Science Lab Disclosure (ZSL-2018-5480) Third-party advisory