SQLi in Megatek Communication System's Azora Wireless Network Management
Summary
| CVE | CVE-2024-12913 |
|---|---|
| State | PUBLISHED |
| Assigner | TR-CERT |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-09-16 12:15:33 UTC |
| Updated | 2026-06-01 15:16:27 UTC |
| Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communication System Azora Wireless Network Management allows SQL Injection. This issue affects Azora Wireless Network Management: through 20250916. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.000270000 probability, percentile 0.080430000 (date 2026-06-02)
Problem Types: CWE-89 | CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Megatek Communication System | Azora Wireless Network Management | affected 20250916 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0253 | [email protected] | siberguvenlik.gov.tr | |
| www.usom.gov.tr/bildirim/tr-25-0253 | [email protected] | www.usom.gov.tr | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Cihan Mehmet DOĞAN (en)
CNA: Berk IMRAN (en)
CNA: Kaan ATMACA (en)
CNA: Secure Future Bilgi Teknolojileri (en)
There are currently no legacy QID mappings associated with this CVE.