CVE-2024-23630

CRITICAL

Motorola MR2600 Firmware - Arbitrary Firmware Upload

Title source: llm
STIX 2.1

Description

An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed.

References (1)

Core 1

Scores

CVSS v3 9.0
EPSS 0.0148
EPSS Percentile 70.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
motorola/mr2600_firmware
Published Jan 26, 2024
Tracked Since Feb 18, 2026