Critical severity9.8NVD Advisory· Published Apr 18, 2019· Updated Jun 17, 2026
CVE-2019-11319
CVE-2019-11319
Description
An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which leads to remote code execution via shell metacharacters in a JSON value.
Affected products
4- cpe:2.3:o:motorola:cx2_firmware:1.01:*:*:*:*:*:*:*
- cpe:2.3:o:motorola:m2_firmware:1.01:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/TeamSeri0us/pocs/blob/master/iot/motorola.pdfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.