Security Advisory

CVE-2024-10195

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-10-20 08:31:03
Last updated 2024-10-21 19:28:34
Assigner VulDB
CVSS score 5.1
State PUBLISHED

Description

A vulnerability was found in Tecno 4G Portable WiFi TR118 V008-20220830. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /goform/goform_get_cmd_process of the component SMS Check. The manipulation of the argument order_by leads to sql injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.