ZeroHour

Vulnerabilities

66 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-4002
+1 in the same advisory: …4003
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

NVD description · AI analysis pending
7.2
group max
<1%
  • motorola q14 firmware
CVE-2024-38281
+2 in the same advisory: …38280 …38279
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.

An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.

NVD description · AI analysis pending
8.6
group max
<1%
  • motorola vigilant fixed lpr coms box firmware
CVE-2024-25360
A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_

A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip.

NVD description · AI analysis pending
5.3<1%
  • motorola cx2l firmware
CVE-2024-23627
+4 in the same advisory: …23626 …23628 …23630 …23629
A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600.

A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

NVD description · AI analysis pending
8.8
group max
4%
  • motorola mr2600 firmware
CVE-2022-3681
A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully b

A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.

NVD description · AI analysis pending
6.5<1%
  • motorola mr2600
CVE-2022-26941
+3 in the same advisory: …26943 …26942 …27813
A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command.

A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An attacker-controllable string is improperly handled, allowing for a write-anything-anywhere scenario. This can be leveraged to obtain arbitrary code execution inside the teds_app binary, which runs with root privileges.

NVD description · AI analysis pending
8.8
group max
<1%
  • motorola mtm5500 firmware
  • motorola mtm5400 firmware
CVE-2022-3407
I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a c

I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user from dialing emergency services. This patch resolves the device's modem reset issue.

NVD description · AI analysis pending
4.3<1%
  • motorola smartphone firmware
CVE-2023-23774
Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception.

Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material and/or gain arbitrary code execution on the device.

NVD description · AI analysis pending
8.4<1%
  • motorola ebts site controller firmware
  • motorola mbts site controller firmware
CVE-2023-23773
Motorola EBTS/MBTS Base Radio fails to check firmware authenticity.

Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.

NVD description · AI analysis pending
8.8<1%
  • motorola ebts base radio firmware
  • motorola mbts base radio firmware
CVE-2023-23770
+1 in the same advisory: …23772
Motorola MBTS Site Controller accepts hard-coded backdoor password.

Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

NVD description · AI analysis pending
9.8
group max
<1%
  • motorola mbts site controller firmware
CVE-2023-23771
Motorola MBTS Base Radio accepts hard-coded backdoor password.

Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

NVD description · AI analysis pending
8.4<1%
  • motorola mbts base radio firmware
CVE-2023-31530
+3 in the same advisory: …31531 …31529 …31528
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.

Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.

NVD description · AI analysis pending
8.82% PoC
  • motorola cx2l firmware
CVE-2022-34885
An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbitrary code.

An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbitrary code.

NVD description · AI analysis pending
6.7<1%
  • motorola mr2600 firmware
CVE-2022-3917
Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.267-38-8 allows attacker with local acce

Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.267-38-8 allows attacker with local access to read partition or RAM data.

NVD description · AI analysis pending
5.5<1%
  • motorola moto e20 firmware
CVE-2022-30276
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement.

The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with RTUs behind the gateway is done by means of the proprietary IPGW protocol (5001/TCP). This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.

NVD description · AI analysis pending
7.5<1%
  • motorola moscad ip gateway firmware
  • motorola ace ip gateway \(4600\) firmware
CVE-2022-30271
+4 in the same advisory: …30270 …30274 …30269 …30272
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a

The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

NVD description · AI analysis pending
9.8
group max
<1%
  • motorola ace1000 firmware
CVE-2022-30273
+1 in the same advisory: …30275
The Motorola MDLC protocol through 2022-05-02 mishandles message integrity.

The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode of operation does not offer message integrity and offers reduced confidentiality above the block level, as demonstrated by an ECB Penguin attack against any block ciphers.

NVD description · AI analysis pending
9.8
group max
<1%
  • motorolasolutions mdlc
CVE-2021-3898
Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead

Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead to the communication channel being accessible by an attacker.

NVD description · AI analysis pending
6.5<1%
  • motorola device help
  • motorola ready for
CVE-2021-38701
Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI.

Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180.

NVD description · AI analysis pending
4.8<1%
  • motorola t008 firmware
  • motorola t100 firmware
  • motorola t101 firmware
  • +1 more
CVE-2021-3459
+1 in the same advisory: …3458
A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary priv

A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.

NVD description · AI analysis pending
6.8
group max
<1%
  • motorola mm1000 firmware
CVE-2020-21937
An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary

An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands.

NVD description · AI analysis pending
9.8
group max
5% PoC ×2
  • motorola cx2 firmware
CVE-2021-3460
The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could

The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communication channel being accessible by an attacker.

NVD description · AI analysis pending
9.8<1%
  • motorola mh702x firmware
CVE-2020-10874
Motorola FX9500 devices allow remote attackers to read database files.

Motorola FX9500 devices allow remote attackers to read database files.

NVD description · AI analysis pending
7.51% PoC
  • motorola fx9500-41324d41-us firmware
  • motorola fx9500-41324d41-ww firmware
  • motorola fx9500-81324d41-us firmware
  • +1 more
CVE-2019-16257
Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI in

Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.

NVD description · AI analysis pending
9.82% PoC
  • motorola motorola firmware
CVE-2019-15513
An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03

An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a device hang.

NVD description · AI analysis pending
7.52% PoC
  • openwrt libuci
  • openwrt cx2l mwr04l firmware
  • openwrt c1 mwr03 firmware