Motorola Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Motorola products.
Products
- Phones20 vulnerabilities
- Binatone Hubble Cameras8 vulnerabilities
- MR26005 vulnerabilities
- Mobile Radio4 vulnerabilities
- Q14 Mesh Router Firmware3 vulnerabilities
- cx2l_firmware2 vulnerabilities
- EBTS/MBTS Base Radio2 vulnerabilities
- ebts_mbts_base_radio2 vulnerabilities
- MBTS Site Controller2 vulnerabilities
- mbts_site_controller2 vulnerabilities
- MM1000 MoCA Adapter2 vulnerabilities
- MR2600 Router2 vulnerabilities
- mr2600_firmware2 vulnerabilities
- mtm5000_series_firmware2 vulnerabilities
- q14_mesh_router_firmware2 vulnerabilities
- smartphone_firmware2 vulnerabilities
- ace1000_firmware1 vulnerability
- Device Help Android App1 vulnerability
- device_help1 vulnerability
- Edge 40 Pro1 vulnerability
- Edge+ 20231 vulnerability
- firmware1 vulnerability
- g341 vulnerability
- g34t1 vulnerability
- g45 5G1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-5804HIGH | Generated title:Motorola Phones com.motorola.motocit Improper Authentication VulnerabilityAn improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive permissions and data. This could allow a local attacker to bypass permission checks and access protected device settings. May 19, 2026 | CVSS8.4v4.0 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-2818MEDIUM | A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files when transferred to a device not paired in Smart Connect. CWE-319Jul 17, 2025 | CVSS5.1v4.0 | EPSS0.112% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1700HIGH | A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the software. CWE-427Jul 17, 2025 | CVSS7.1v4.0 | EPSS0.148% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access. CWE-276Jun 11, 2025 | CVSS2.4v4.0 | EPSS0.107% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service. CWE-476Jun 11, 2025 | CVSS2.4v4.0 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-45880HIGH | A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the system function to execute commands for setting parameters such as MAC address without proper input filtering. This allows malicious users to inject and execute arbitrary commands. CWE-78Oct 8, 2024 | CVSS8.0v3.1 | EPSS0.942% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4001HIGH | An authentication bypass vulnerability could allow an attacker to access API functions without authentication. CWE-287Jul 31, 2024 | CVSS7.3v3.1 | EPSS0.342% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4002HIGH | A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request. | CVSS7.2v3.1 | EPSS0.954% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request. CWE-400Jul 31, 2024 | CVSS2.7v3.1 | EPSS0.396% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data. CWE-927May 3, 2024 | CVSS2.8v3.1 | EPSS0.147% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data. CWE-926May 3, 2024 | CVSS2.8v3.1 | EPSS0.143% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-3109MEDIUM | A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files. CWE-321May 3, 2024 | CVSS6.3v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-3108MEDIUM | An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization. CWE-927May 3, 2024 | CVSS5.5v3.1 | EPSS0.153% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41830MEDIUM | An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization. CWE-36May 3, 2024 | CVSS6.5v3.1 | EPSS0.197% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41828MEDIUM | An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider. CWE-927May 3, 2024 | CVSS4.4v3.1 | EPSS0.163% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41826MEDIUM | A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission. CWE-927May 3, 2024 | CVSS5.1v3.1 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files. CWE-22May 3, 2024 | CVSS2.8v3.1 | EPSS0.183% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data. CWE-927May 3, 2024 | CVSS2.8v3.1 | EPSS0.143% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-41823MEDIUM | An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities. CWE-926May 3, 2024 | CVSS4.4v3.1 | EPSS0.158% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41822MEDIUM | An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands. CWE-926May 3, 2024 | CVSS4.8v3.1 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41821MEDIUM | A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information. CWE-926May 3, 2024 | CVSS5.0v3.1 | EPSS0.149% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41820MEDIUM | An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices. CWE-927May 3, 2024 | CVSS5.0v3.1 | EPSS0.149% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41819MEDIUM | A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers. CWE-285May 3, 2024 | CVSS6.1v3.1 | EPSS0.142% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41818MEDIUM | An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs. CWE-921May 3, 2024 | CVSS5.0v3.1 | EPSS0.149% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information. CWE-927May 3, 2024 | CVSS2.8v3.1 | EPSS0.143% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |