CVE-2024-45880

HIGH

Motorola CX2L <1.0.2 - Command Injection

Title source: llm
STIX 2.1

Description

A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the system function to execute commands for setting parameters such as MAC address without proper input filtering. This allows malicious users to inject and execute arbitrary commands.

Scores

CVSS v3 8.0
EPSS 0.0092
EPSS Percentile 55.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Published Oct 08, 2024
Tracked Since Feb 18, 2026