Junglewise Threat Intelligence

CVE-2024-12913: Megatek Azora Wireless Network Management SQL injection

CVE-2024-12913 · Severity: high · CVSS 8.8 · Published 2025-09-16

Executive brief

Megatek Azora Wireless Network Management, a system used to manage wireless network infrastructure, contains a security vulnerability that could allow an attacker to gain unauthorized access to its database. By exploiting this flaw, a local user could potentially view, modify, or delete sensitive network configuration data and administrative information. This could lead to a total loss of confidentiality and control over the wireless network management environment.

Technical details

An SQL injection vulnerability (CWE-89) exists in Megatek Communication System Azora Wireless Network Management due to improper neutralization of special elements used in SQL commands. The vulnerability is exploitable by a local attacker with low privileges (AV:L/PR:L). Successful exploitation allows the attacker to execute arbitrary SQL queries, potentially leading to full data exfiltration, modification, or a complete takeover of the management system. As of the latest advisory update, the vendor has not confirmed the completion of a fix, and the vulnerability affects versions through September 16, 2025.

Affected products

  • Megatek Communication System Azora Wireless Network Management through 20250916

Timeline

  • 2025-09-16: advisory: Initial advisory published by TR-CERT (USOM)
  • 2025-09-16: disclosed

References