Vulnerabilities
66 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-4002 +1 in the same advisory: …4003 | A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request. A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request. NVD description · AI analysis pending | 7.2 group max | <1% |
| — | ||
| CVE-2024-38281 | An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device. An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device. NVD description · AI analysis pending | 8.6 group max | <1% |
| — | ||
| CVE-2024-25360 | A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_ A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2024-23627 | A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed. NVD description · AI analysis pending | 8.8 group max | 4% |
| — | ||
| CVE-2022-3681 | A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully b A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2022-26941 | A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An attacker-controllable string is improperly handled, allowing for a write-anything-anywhere scenario. This can be leveraged to obtain arbitrary code execution inside the teds_app binary, which runs with root privileges. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2022-3407 | I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a c I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user from dialing emergency services. This patch resolves the device's modem reset issue. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2023-23774 | Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material and/or gain arbitrary code execution on the device. NVD description · AI analysis pending | 8.4 | <1% |
| — | ||
| CVE-2023-23773 | Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2023-23770 +1 in the same advisory: …23772 | Motorola MBTS Site Controller accepts hard-coded backdoor password. Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2023-23771 | Motorola MBTS Base Radio accepts hard-coded backdoor password. Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled. NVD description · AI analysis pending | 8.4 | <1% |
| — | ||
| CVE-2023-31530 | Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter. Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2022-34885 | An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbitrary code. An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbitrary code. NVD description · AI analysis pending | 6.7 | <1% |
| — | ||
| CVE-2022-3917 | Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.267-38-8 allows attacker with local acce Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.267-38-8 allows attacker with local access to read partition or RAM data. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2022-30276 | The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with RTUs behind the gateway is done by means of the proprietary IPGW protocol (5001/TCP). This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2022-30271 | The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2022-30273 +1 in the same advisory: …30275 | The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode of operation does not offer message integrity and offers reduced confidentiality above the block level, as demonstrated by an ECB Penguin attack against any block ciphers. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2021-3898 | Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead to the communication channel being accessible by an attacker. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2021-38701 | Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2021-3459 +1 in the same advisory: …3458 | A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary priv A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter. NVD description · AI analysis pending | 6.8 group max | <1% |
| — | ||
| CVE-2020-21937 | An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands. NVD description · AI analysis pending | 9.8 group max | 5% | PoC ×2 |
| — | |
| CVE-2021-3460 | The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communication channel being accessible by an attacker. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2020-10874 | Motorola FX9500 devices allow remote attackers to read database files. Motorola FX9500 devices allow remote attackers to read database files. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2019-16257 | Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI in Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-15513 | An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a device hang. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — |