CVE-2018-25147: Microhardcorp Bullet-3g Firmware

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.

Affected products

Published 2025-12-24. Last modified 2026-06-17.