VYPR

Vendor CVEs

Motorola

All CVEs

145 total · sorted by risk
  • CVE-2014-9784HigJul 11, 2016
    risk 0.51cvss 7.8epss 0.01

    Multiple buffer overflows in drivers/char/diag/diag_debugfs.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28442449 and Qualcomm internal bug…

  • CVE-2022-30276HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links)…

  • CVE-2022-30275HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini…

  • CVE-2020-21934HigJul 21, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed.

  • CVE-2020-21933HigJul 21, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.

  • CVE-2020-10875HigMar 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files such as /include/viewtagdb.psp.

  • CVE-2020-10874HigMar 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Motorola FX9500 devices allow remote attackers to read database files.

  • CVE-2019-15513HigAug 23, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a…

  • CVE-2019-13129HigJul 1, 2019
    risk 0.49cvss 7.5epss 0.01

    On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8010 and UDP port 8080. It is caused by snprintf and inappropriate length handling.

  • CVE-2015-7936HigDec 23, 2015
    risk 0.49cvss 7.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password.

  • CVE-2015-7935HigDec 23, 2015
    risk 0.49cvss 7.5epss 0.02

    Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2018-12499HigJul 2, 2018
    risk 0.48cvss 7.4epss 0.00

    The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one such instance, it was identified that the device was…

  • CVE-2022-4002HigJul 31, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

  • CVE-2022-4001HigJul 31, 2024
    risk 0.47cvss 7.3epss 0.00

    An authentication bypass vulnerability could allow an attacker to access API functions without authentication.

  • CVE-2023-23773HigAug 29, 2023
    risk 0.47cvss 7.2epss 0.00

    Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave…

  • CVE-2023-23772HigAug 29, 2023
    risk 0.47cvss 7.2epss 0.00

    Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material,…

  • CVE-2022-34885HigJan 30, 2023
    risk 0.47cvss 7.2epss 0.00

    An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbitrary code.

  • CVE-2022-30272HigJul 26, 2022
    risk 0.47cvss 7.2epss 0.00

    The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where…

  • CVE-2025-1700HigJul 17, 2025
    risk 0.46cvss 7.0epss 0.00

    A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the software.

  • CVE-2023-38291HigApr 22, 2024
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC…

  • CVE-2021-3898MedApr 22, 2022
    risk 0.44cvss 6.8epss 0.00

    Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead to the communication channel being accessible by an attacker.

  • CVE-2021-3788MedNov 12, 2021
    risk 0.44cvss 6.8epss 0.00

    An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.

  • CVE-2021-3459MedAug 17, 2021
    risk 0.44cvss 6.8epss 0.00

    A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.

  • CVE-2017-9497MedJul 31, 2017
    risk 0.44cvss 6.8epss 0.00

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to execute arbitrary commands as root by pulling up the diagnostics menu on the set-top box, and then posting to a Web Inspector route.

  • CVE-2023-41830MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.00

    An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization. 

  • CVE-2022-3681MedOct 27, 2023
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.

  • CVE-2021-3793MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.01

    An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware…

  • CVE-2021-3791MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.00

    An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password.

  • CVE-2021-3790MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.00

    A buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same network to perform a denial-of-service attack against the device.

  • CVE-2021-3787MedNov 12, 2021
    risk 0.42cvss 6.4epss 0.00

    A vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT credentials that could result in unauthorized access to backend Hubble services.

  • CVE-2024-3109MedMay 3, 2024
    risk 0.41cvss 6.3epss 0.00

    A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.

  • CVE-2017-9493MedJul 31, 2017
    risk 0.41cvss 6.3epss 0.01

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to conduct successful forced-pairing attacks (between an RF4CE remote and a set-top box) by repeatedly transmitting the same pairing code.

  • CVE-2023-41819MedMay 3, 2024
    risk 0.40cvss 6.1epss 0.00

    A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers. 

  • CVE-2021-3458MedAug 17, 2021
    risk 0.40cvss 6.1epss 0.00

    The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.

  • CVE-2024-3108MedMay 3, 2024
    risk 0.36cvss 5.5epss 0.00

    An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization. 

  • CVE-2017-9498MedJul 31, 2017
    risk 0.36cvss 5.5epss 0.00

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access. In other words, there is no protection mechanism involving…

  • CVE-2016-6678MedOct 10, 2016
    risk 0.36cvss 5.5epss 0.00

    The Motorola USBNet driver in Android before 2016-10-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 29914434.

  • CVE-2020-21936MedJul 21, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentication.

  • CVE-2020-21932MedJul 21, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially authorized token and uid.

  • CVE-2019-11321MedApr 18, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices.

  • CVE-2017-9494MedJul 31, 2017
    risk 0.35cvss 5.3epss 0.01

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspector that is accessible from the public Internet.

  • CVE-2024-25360MedFeb 12, 2024
    risk 0.34cvss 5.3epss 0.00

    A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip.

  • CVE-2021-3792MedNov 12, 2021
    risk 0.34cvss 5.3epss 0.00

    Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker.

  • CVE-2023-41826MedMay 3, 2024
    risk 0.33cvss 5.1epss 0.00

    A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission. 

  • CVE-2023-41821MedMay 3, 2024
    risk 0.33cvss 5.0epss 0.00

    A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information. 

  • CVE-2023-41820MedMay 3, 2024
    risk 0.33cvss 5.0epss 0.00

    An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices. 

  • CVE-2023-41818MedMay 3, 2024
    risk 0.33cvss 5.0epss 0.00

    An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs. 

  • CVE-2023-41816MedMay 3, 2024
    risk 0.33cvss 5.0epss 0.00

    An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database. 

  • CVE-2023-41829MedMar 4, 2024
    risk 0.33cvss 5.0epss 0.00

    An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.

  • CVE-2023-41827MedMar 4, 2024
    risk 0.33cvss 5.1epss 0.00

    An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.