A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the system function to execute commands for setting parameters such as MAC address without proper input filtering. This allows malicious users to inject and execute arbitrary commands.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/N1nEmAn/wp/blob/main/m0tOrol%40-Cx2l.pdf |
|
History
Tue, 08 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Motorola
Motorola cx2l Firmware |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:o:motorola:cx2l_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Motorola
Motorola cx2l Firmware |
|
| Metrics |
cvssV3_1
|
Tue, 08 Oct 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the system function to execute commands for setting parameters such as MAC address without proper input filtering. This allows malicious users to inject and execute arbitrary commands. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-08T00:00:00
Updated: 2024-10-08T15:27:13.517Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-45880
Updated: 2024-10-08T15:26:59.405Z
Status : Awaiting Analysis
Published: 2024-10-08T15:15:15.217
Modified: 2024-10-10T12:56:30.817
Link: CVE-2024-45880
No data.