CVE-2018-25147

7.5

Microhard Systems · Multiple Cellular Ethernet and Serial Gateways

Multiple Microhard Systems gateway devices contain hardcoded default credentials that cannot be changed, allowing unauthenticated attackers to gain root-level access to the affected hardware.

Executive summary

Multiple Microhard Systems industrial gateways are vulnerable to unauthorized root-level access due to immutable, hardcoded default credentials.

Vulnerability

The affected devices utilize hardcoded credentials within their Linux distribution image that cannot be altered through standard administrative operations. An unauthenticated attacker can exploit this by logging into the device with these known, predefined credentials to establish full root-level control.

Business impact

Successful exploitation of this vulnerability grants an attacker full root access to industrial gateway devices. This compromise can lead to complete loss of confidentiality, integrity, and availability of the device, potentially allowing an attacker to intercept critical industrial data, modify network traffic, or pivot into restricted segments of the operational technology network. With a CVSS score of 7.5, this high-severity flaw represents a significant risk to operational continuity and system security.

Remediation

Immediate Action: Contact Microhard Systems support to obtain firmware updates that remove or allow for the modification of these hardcoded credentials. If updates are unavailable, remove these devices from internet-facing networks immediately.

Proactive Monitoring: Review device access logs for successful logins originating from unknown or unauthorized IP addresses. Monitor for unusual configuration changes or unauthorized service modifications on the gateways.

Compensating Controls: Deploy a hardware or software firewall to restrict access to the management interfaces of these gateways to trusted, internal IP addresses only. Implement strict network segmentation to ensure these devices are isolated from critical business systems.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the ExploitDB entry 45040.

Analyst recommendation

The presence of immutable hardcoded credentials in industrial hardware is a critical security deficiency that poses a severe risk to infrastructure. Administrators must prioritize the isolation of these devices from all external networks and coordinate with the vendor to implement secure authentication mechanisms. Failure to address this vulnerability leaves the affected gateways open to complete unauthorized control by external actors.

More Microhard Systems CVEs

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.