CVE-2024-23630

An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:motorola:mr2600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mr2600:-:*:*:*:*:*:*:*

History

01 Feb 2024, 19:56

Type Values Removed Values Added
CPE cpe:2.3:o:motorola:mr2600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mr2600:-:*:*:*:*:*:*:*
References () https://blog.exodusintel.com/2024/01/25/motorola-mr2600-arbitrary-firmware-upload-vulnerability/ - () https://blog.exodusintel.com/2024/01/25/motorola-mr2600-arbitrary-firmware-upload-vulnerability/ - Third Party Advisory
First Time Motorola mr2600
Motorola
Motorola mr2600 Firmware
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

26 Jan 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-26 00:15

Updated : 2024-02-28 20:54


NVD link : CVE-2024-23630

Mitre link : CVE-2024-23630

CVE.ORG link : CVE-2024-23630


JSON object : View

Products Affected

motorola

  • mr2600
  • mr2600_firmware
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type