CVE-2018-25143
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
24/12/2025
Last modified:
24/12/2025
Description
Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privileges.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH



