CVE-2024-23628
CRITICALMotorola MR2600 - Command Injection via SaveStaticRouteIPv6Params
Title source: llmDescription
A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
References (1)
Core 1
Core References
Third Party Advisory third-party-advisory
https://blog.exodusintel.com/2024/01/25/motorola-mr2600-savestaticrouteipv6params-command-injection-vulnerability/
Scores
CVSS v3
9.0
EPSS
0.0317
EPSS Percentile
86.4%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-77
Status
published
Products (1)
motorola/mr2600_firmware
Published
Jan 26, 2024
Tracked Since
Feb 18, 2026