Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-25149. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Microhard Systems' cellular gateways, allowing an attacker to change the admin password without user interaction. The PoC includes a crafted HTML form that submits a password change request to the vulnerable endpoint.
Description
Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated users into loading a specially crafted page.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Microhard Systems' cellular gateways, allowing an attacker to change the admin password without user interaction. The PoC includes a crafted HTML form that submits a password change request to the vulnerable endpoint.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N