CVE-2024-23630

CRITICAL

Motorola Mr2600 Firmware - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed.

References (1)

Core 1

Scores

CVSS v3 9.0
EPSS 0.0012
EPSS Percentile 30.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
motorola/mr2600_firmware
Published Jan 26, 2024
Tracked Since Feb 18, 2026