Motorola Vulnerabilities and Affected Products
Vulnerabilities associated with Phones.
Products
Clear product- Phones20 vulnerabilities
- Binatone Hubble Cameras8 vulnerabilities
- MR26005 vulnerabilities
- Mobile Radio4 vulnerabilities
- Q14 Mesh Router Firmware3 vulnerabilities
- cx2l_firmware2 vulnerabilities
- EBTS/MBTS Base Radio2 vulnerabilities
- ebts_mbts_base_radio2 vulnerabilities
- MBTS Site Controller2 vulnerabilities
- mbts_site_controller2 vulnerabilities
- MM1000 MoCA Adapter2 vulnerabilities
- MR2600 Router2 vulnerabilities
- mr2600_firmware2 vulnerabilities
- mtm5000_series_firmware2 vulnerabilities
- q14_mesh_router_firmware2 vulnerabilities
- smartphone_firmware2 vulnerabilities
- ace1000_firmware1 vulnerability
- Device Help Android App1 vulnerability
- device_help1 vulnerability
- Edge 40 Pro1 vulnerability
- Edge+ 20231 vulnerability
- firmware1 vulnerability
- g341 vulnerability
- g34t1 vulnerability
- g45 5G1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-5804HIGH | Generated title:Motorola Phones com.motorola.motocit Improper Authentication VulnerabilityAn improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive permissions and data. This could allow a local attacker to bypass permission checks and access protected device settings. May 19, 2026 | CVSS8.4v4.0 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data. CWE-927May 3, 2024 | CVSS2.8v3.1 | EPSS0.147% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data. CWE-926May 3, 2024 | CVSS2.8v3.1 | EPSS0.143% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-3109MEDIUM | A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files. CWE-321May 3, 2024 | CVSS6.3v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-3108MEDIUM | An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization. CWE-927May 3, 2024 | CVSS5.5v3.1 | EPSS0.153% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41830MEDIUM | An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization. CWE-36May 3, 2024 | CVSS6.5v3.1 | EPSS0.197% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41828MEDIUM | An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider. CWE-927May 3, 2024 | CVSS4.4v3.1 | EPSS0.163% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41826MEDIUM | A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission. CWE-927May 3, 2024 | CVSS5.1v3.1 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files. CWE-22May 3, 2024 | CVSS2.8v3.1 | EPSS0.183% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data. CWE-927May 3, 2024 | CVSS2.8v3.1 | EPSS0.143% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-41823MEDIUM | An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities. CWE-926May 3, 2024 | CVSS4.4v3.1 | EPSS0.158% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41822MEDIUM | An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands. CWE-926May 3, 2024 | CVSS4.8v3.1 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41821MEDIUM | A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information. CWE-926May 3, 2024 | CVSS5.0v3.1 | EPSS0.149% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41820MEDIUM | An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices. CWE-927May 3, 2024 | CVSS5.0v3.1 | EPSS0.149% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41819MEDIUM | A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers. CWE-285May 3, 2024 | CVSS6.1v3.1 | EPSS0.142% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41818MEDIUM | An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs. CWE-921May 3, 2024 | CVSS5.0v3.1 | EPSS0.149% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information. CWE-927May 3, 2024 | CVSS2.8v3.1 | EPSS0.143% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-41816MEDIUM | An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database. CWE-926May 3, 2024 | CVSS5.0v3.1 | EPSS0.138% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41829MEDIUM | An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization. CWE-926Mar 4, 2024 | CVSS5.0v3.1 | EPSS0.154% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41827MEDIUM | An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI. CWE-926Mar 4, 2024 | CVSS5.1v3.1 | EPSS0.162% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |