CVE-2024-57237
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-57237 is a newly discovered cross-site scripting (XSS) vulnerability affecting the Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05. The vulnerability lies in the /reqproc/proc_get endpoint, which does not adequately sanitize the cmd parameter. An attacker can exploit this weakness by injecting malicious JavaScript code, which the browser then executes due to the response being served with a Content-Type of text/html. Successful attacks could lead to unauthorized access to user data or sessions. Users are advised to update their devices as soon as a patch becomes available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.