Junglewise Threat Intelligence

CVE-2024-12143: Mobilteg Mikro Hand Terminal SQL injection in MikroDB

CVE-2024-12143 · Severity: critical · CVSS 9.8 · Published 2025-06-27

Executive brief

Mobilteg Mikro Hand Terminal, a mobile device used for inventory and warehouse management, contains a critical security flaw in its database component. An attacker can exploit this vulnerability to gain unauthorized access to the underlying database, potentially allowing them to steal sensitive business data, modify records, or disrupt operations. As of the latest report, the vendor has not confirmed a fix, posing a significant risk to organizations using these handheld terminals.

Technical details

An SQL injection vulnerability exists in the MikroDB component of Mobilteg Mobile Informatics Mikro Hand Terminal. The flaw stems from improper neutralization of special elements used in SQL commands, allowing an unauthenticated attacker to send malicious queries over the network. Successful exploitation grants the attacker full access to the database, including the ability to read, modify, or delete data (C/I/A impact). The vulnerability is exploitable remotely without user interaction. At the time of reporting, a patch has not been confirmed by the vendor.

Affected products

  • Mobilteg Mobile Informatics Mikro Hand Terminal - MikroDB

Timeline

  • 2025-06-27: disclosed: Initial disclosure by TR-CERT (USOM)
  • 2025-06-27: advisory: CVE published to NVD

References