Products that incorporate the Microhard BulletLTE-NA2 and...
        
  High severity
        
          Unreviewed
      
        Published
          Jun 8, 2025 
          to the GitHub Advisory Database
          •
          Updated Jun 8, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Jun 8, 2025 
    
  
        Published to the GitHub Advisory Database
      Jun 8, 2025 
    
  
        Last updated
      Jun 8, 2025 
    
  
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFMAC command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). This issue has not been generally fixed at the time of this CVE record's first publishing.
References