CVE-2018-25148
8.8Microhard · Multiple Industrial Gateways (IPn4G, IPn3Gb, IPn4Gb, Bullet-3G, VIP4Gb, VIP4G, Dragon-LTE)
Multiple Microhard industrial gateways contain authenticated remote code execution vulnerabilities in the admin interface, allowing attackers to execute commands with root privileges via crontab jobs.
Executive summary
Several Microhard industrial cellular gateways are vulnerable to authenticated remote code execution, which allows an attacker to gain full root control over the affected device.
Vulnerability
The vulnerability resides in hidden and undocumented features within the administrative web interface. By sending specifically crafted POST requests to endpoints such as /cgi-bin/webif/system-crontabs.sh, an authenticated attacker can inject arbitrary system commands into crontab jobs or startup scripts, which then execute with root-level privileges.
Business impact
Successful exploitation of these vulnerabilities provides an attacker with complete control over the industrial gateway. This can lead to the disabling of security features like firewalls, the exfiltration of sensitive network data, or the use of the device as a pivot point to attack other internal systems. Given the CVSS score of 8.8, this represents a critical risk to operational technology environments where these gateways manage critical data flow.
Remediation
Immediate Action: Contact the vendor or consult the official support portal to determine if a firmware update is available for your specific build, as no public patch is explicitly identified in the provided data. If no patch is available, restrict access to the administrative web interface to trusted management IP addresses only.
Proactive Monitoring: Review system logs for unauthorized changes to crontab entries or system startup scripts. Monitor for suspicious outbound traffic originating from the gateway to external IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an internal network access control list to block unauthorized access to the /cgi-bin/webif/ directory on the affected devices.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exploit is available via the Exploit Database (EDB-ID: 45038).
Analyst recommendation
Due to the high severity of this vulnerability and the availability of a public exploit, administrators must treat these devices as high-risk assets. Immediately restrict network access to the administrative web interfaces of all affected Microhard gateways and prioritize obtaining firmware updates from the vendor to remediate the underlying flaw.
More Microhard CVEs
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- ExploitDB-45038 Exploit / PoC
- Microhard Systems Product Web Page
- Zero Science Lab Disclosure (ZSL-2018-5479) Third-party advisory