An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a device hang.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
21 Nov 2024, 04:28
Type | Values Removed | Values Added |
---|---|---|
References | () https://git.openwrt.org/?p=project/uci.git%3Ba=commitdiff%3Bh=19e29ffc15dbd958e8e6a648ee0982c68353516f - | |
References | () https://github.com/TeamSeri0us/pocs/blob/master/iot/morouter/motorola%E8%B7%AF%E7%94%B1%E5%99%A8%E6%96%87%E4%BB%B6%E8%A7%A3%E9%94%81%E6%BC%8F%E6%B4%9E.pdf - Exploit, Third Party Advisory | |
References | () https://lists.infradead.org/pipermail/openwrt-devel/2019-November/019736.html - | |
References | () https://lists.openwrt.org/pipermail/openwrt-devel/2019-November/025453.html - |
07 Nov 2023, 03:05
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2019-08-23 07:15
Updated : 2024-11-21 04:28
NVD link : CVE-2019-15513
Mitre link : CVE-2019-15513
CVE.ORG link : CVE-2019-15513
JSON object : View
Products Affected
motorola
- cx2l_mwr04l
- c1_mwr03_firmware
- c1_mwr03
- cx2l_mwr04l_firmware
openwrt
- libuci
CWE
CWE-667
Improper Locking