Products that incorporate the Microhard BulletLTE-NA2 and...
High severity
Unreviewed
Published
Jun 8, 2025
to the GitHub Advisory Database
•
Updated Jun 8, 2025
Description
Published by the National Vulnerability Database
Jun 8, 2025
Published to the GitHub Advisory Database
Jun 8, 2025
Last updated
Jun 8, 2025
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNNETSP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.
References