CVE-2024-23630

An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:motorola:mr2600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mr2600:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References () https://blog.exodusintel.com/2024/01/25/motorola-mr2600-arbitrary-firmware-upload-vulnerability/ - Third Party Advisory () https://blog.exodusintel.com/2024/01/25/motorola-mr2600-arbitrary-firmware-upload-vulnerability/ - Third Party Advisory
CVSS v2 : 7.7
v3 : 8.8
v2 : 7.7
v3 : 9.0

01 Feb 2024, 19:56

Type Values Removed Values Added
References () https://blog.exodusintel.com/2024/01/25/motorola-mr2600-arbitrary-firmware-upload-vulnerability/ - () https://blog.exodusintel.com/2024/01/25/motorola-mr2600-arbitrary-firmware-upload-vulnerability/ - Third Party Advisory
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Motorola mr2600
Motorola
Motorola mr2600 Firmware
CPE cpe:2.3:o:motorola:mr2600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mr2600:-:*:*:*:*:*:*:*

26 Jan 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-26 00:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-23630

Mitre link : CVE-2024-23630

CVE.ORG link : CVE-2024-23630


JSON object : View

Products Affected

motorola

  • mr2600_firmware
  • mr2600
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type