Motorola Vulnerabilities and Affected Products
Vulnerabilities associated with MR2600.
Products
Clear product- Phones20 vulnerabilities
- Binatone Hubble Cameras8 vulnerabilities
- MR26005 vulnerabilities
- Mobile Radio4 vulnerabilities
- Q14 Mesh Router Firmware3 vulnerabilities
- cx2l_firmware2 vulnerabilities
- EBTS/MBTS Base Radio2 vulnerabilities
- ebts_mbts_base_radio2 vulnerabilities
- MBTS Site Controller2 vulnerabilities
- mbts_site_controller2 vulnerabilities
- MM1000 MoCA Adapter2 vulnerabilities
- MR2600 Router2 vulnerabilities
- mr2600_firmware2 vulnerabilities
- mtm5000_series_firmware2 vulnerabilities
- q14_mesh_router_firmware2 vulnerabilities
- smartphone_firmware2 vulnerabilities
- ace1000_firmware1 vulnerability
- Device Help Android App1 vulnerability
- device_help1 vulnerability
- Edge 40 Pro1 vulnerability
- Edge+ 20231 vulnerability
- firmware1 vulnerability
- g341 vulnerability
- g34t1 vulnerability
- g45 5G1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-23630CRITICAL | Motorola MR2600 Arbitrary Firmware Upload VulnerabilityAn arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed. CWE-434Jan 25, 2024 | CVSS9.0v3.1 | EPSS1.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23629CRITICAL | Motorola MR2600 Authentication Bypass VulnerabilityAn authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information. | CVSS9.6v3.1 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23628CRITICAL | Motorola MR2600 SaveStaticRouteIPv6Params Command Injection VulnerabilityA command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed. CWE-77Jan 25, 2024 | CVSS9.0v3.1 | EPSS3.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23627CRITICAL | Motorola MR2600 SaveStaticRouteIPv4Params Command Injection VulnerabilityA command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed. CWE-77Jan 25, 2024 | CVSS9.0v3.1 | EPSS3.54% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23626CRITICAL | Motorola MR2600 SaveSysLogParams Command Injection VulnerabilityA command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed. CWE-77Jan 25, 2024 | CVSS9.0v3.1 | EPSS3.54% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |