Motorola CVE Vulnerabilities & CVE List (91)

Products (CPE): — CVEs: 91

Motorola vulnerability overview

Aggregates CVE and security vulnerability intelligence across all Motorola-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk path handling, vendor risk input validation, and vendor risk cross-site scripting; exposure may include vendor impact file overwrite in vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 120 of 91 CVEs
«« First « Prev Page 1 / 5 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-4003 A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request. [email protected] 2.7 0.14% 2024-07-31 2024-08-13
CVE-2022-4002 A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request. [email protected] 7.2 0.49% 2024-07-31 2024-08-13
CVE-2024-38281 An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device. [email protected] 8.6 0.26% 2024-06-13 2024-11-21
CVE-2024-38280 An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text. [email protected] 7.0 0.09% 2024-06-13 2024-11-21
CVE-2024-38279 The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes. [email protected] 5.1 0.03% 2024-06-13 2024-11-21
CVE-2024-25360 A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip. [email protected] 5.3 0.11% 2024-02-12 2024-11-21
CVE-2024-23630 An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed. [email protected] 9.0 0.12% 2024-01-26 2024-11-21
CVE-2024-23629 An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information. [email protected] 9.6 0.06% 2024-01-26 2024-11-21
CVE-2024-23628 A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed. [email protected] 9.0 0.14% 2024-01-26 2024-11-21
CVE-2024-23627 A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed. [email protected] 9.0 1.17% 2024-01-26 2024-11-21
CVE-2024-23626 A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed. [email protected] 9.0 1.17% 2024-01-26 2024-11-21
CVE-2022-3681 A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network. [email protected] 6.5 0.05% 2023-10-27 2024-11-21
CVE-2022-27813 Motorola MTM5000 series firmwares lack properly configured memory protection of pages shared between the OMAP-L138 ARM and DSP cores. The SoC provides two memory protection units, MPU1 and MPU2, to enforce the trust boundary between the two cores. Since both units are left unconfigured by the firmwares, an adversary with control over either core can trivially gain code execution on the other, by overwriting code located in shared RAM or DDR2 memory regions. [email protected] 8.1 0.05% 2023-10-19 2024-11-21
CVE-2022-26943 The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using a tick count register as its sole entropy source. Low boottime entropy and limited re-seeding of the pool renders the authentication challenge vulnerable to two attacks. First, due to the limited boottime pool entropy, an adversary can derive the contents of the entropy pool by an exhaustive search of possible values, based on an observed authentication challenge. Second, an adversary can use knowle [email protected] 8.8 0.17% 2023-10-19 2024-11-21
CVE-2022-26942 The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE) modules. Two modules are used, one responsible for KVL key management and the other for TETRA cryptographic functionality. In both modules, an adversary with non-secure supervisor level code execution can exploit the issue in order to gain secure supervisor code execution within the TEE. This constitutes a full break of the TEE module, exposing the device key as well as any TE [email protected] 8.2 0.06% 2023-10-19 2024-11-21
CVE-2022-26941 A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An attacker-controllable string is improperly handled, allowing for a write-anything-anywhere scenario. This can be leveraged to obtain arbitrary code execution inside the teds_app binary, which runs with root privileges. [email protected] 9.6 0.07% 2023-10-19 2024-11-21
CVE-2022-3407 I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user from dialing emergency services. This patch resolves the device's modem reset issue. [email protected] 4.9 0.03% 2023-09-01 2024-11-21
CVE-2023-23774 Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material and/or gain arbitrary code execution on the device. [email protected] 8.4 0.03% 2023-08-29 2024-11-21
CVE-2023-23773 Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device. [email protected] 7.2 0.03% 2023-08-29 2024-11-21
CVE-2023-23772 Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device. [email protected] 7.2 0.03% 2023-08-29 2024-11-21
«« First « Prev Page 1 / 5 Next »
cvelogic Threat Intelligence