Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is...
Moderate severity
Unreviewed
Published
Feb 3, 2025
to the GitHub Advisory Database
•
Updated Feb 12, 2025
Description
Published by the National Vulnerability Database
Feb 3, 2025
Published to the GitHub Advisory Database
Feb 3, 2025
Last updated
Feb 12, 2025
Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endpoint. The vulnerability arises because the cmd parameter does not properly sanitize input and the response is served with a Content-Type of text/html. This behavior allows the browser to execute injected JavaScript code.
References