A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
The vulnerability consists of insufficient filtering of input data passed to the 'SaveStaticRouteIPv6Params' parameter, which allows injection and execution of arbitrary system commands. An attacker operating from a local network segment (AV:A vector) can craft an appropriate request containing a malicious payload. Although access requires authentication, the authorization mechanism can be bypassed, which practically eliminates this protective barrier.
Successful exploitation of the vulnerability gives the attacker full control over the device — the ability to execute arbitrary system commands, which may lead to violations of confidentiality, integrity and availability of the system and the entire network behind it.
Patches available from the manufacturer should be applied in accordance with references. Until the fix is implemented, it is recommended to restrict access to the device management interface only to trusted hosts and isolate the router from untrusted network segments.
Motorola MR2600 (firmware) — versions indicated in manufacturer references
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HMotorola Mr2600
HWMotorolaall versionsMotorola Mr2600 Firmware
OSMotorolaall versions
Related vulnerabilities
Command injection w parametrze SaveSysLogParams routera Motorola MR2600
Command injection w parametrze SaveStaticRouteIPv4Params routera Motorola MR2600
Authentication bypass w routerze Motorola MR2600 — dostęp do chronionych zasobów
Motorola MR2600 – dowolny upload firmware umożliwiający RCE
An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with eleva...