CVE-2018-25145: Microhardcorp Bullet-3g Firmware

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from multiple directories including '/www', '/etc/m_cli/', and '/tmp' to access system passwords and network settings.

Affected products

Published 2025-12-24. Last modified 2026-06-17.