Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL queries by injecting malicious SQL code into the order_by parameter.
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00038}

epss

{'score': 0.00048}


Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Description Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL queries by injecting malicious SQL code into the order_by parameter.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-02-03T00:00:00.000Z

Updated: 2025-02-12T19:13:56.803Z

Reserved: 2025-01-09T00:00:00.000Z

Link: CVE-2024-57238

cve-icon Vulnrichment

Updated: 2025-02-05T15:15:02.566Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-03T19:15:13.177

Modified: 2025-02-12T20:15:35.620

Link: CVE-2024-57238

cve-icon Redhat

No data.