CRITICAL🇵🇱 Wersja polska

CVE-2024-23628

CVSS 9.0v3.1pub. 2024-01-26upd. 2024-11-21

A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

🤖 AI Analysis
How it works

The vulnerability consists of insufficient filtering of input data passed to the 'SaveStaticRouteIPv6Params' parameter, which allows injection and execution of arbitrary system commands. An attacker operating from a local network segment (AV:A vector) can craft an appropriate request containing a malicious payload. Although access requires authentication, the authorization mechanism can be bypassed, which practically eliminates this protective barrier.

Impact

Successful exploitation of the vulnerability gives the attacker full control over the device — the ability to execute arbitrary system commands, which may lead to violations of confidentiality, integrity and availability of the system and the entire network behind it.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with references. Until the fix is implemented, it is recommended to restrict access to the device management interface only to trusted hosts and isolate the router from untrusted network segments.

Who is affected

Motorola MR2600 (firmware) — versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Motorola Mr2600

    HW
    Motorola
    all versions
  • Motorola Mr2600 Firmware

    OS
    Motorola
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-23626CRITICAL9.0PL ✓same product

Command injection w parametrze SaveSysLogParams routera Motorola MR2600

CVE-2024-23627CRITICAL9.0PL ✓same product

Command injection w parametrze SaveStaticRouteIPv4Params routera Motorola MR2600

CVE-2024-23629CRITICAL9.6PL ✓same product

Authentication bypass w routerze Motorola MR2600 — dostęp do chronionych zasobów

CVE-2024-23630CRITICAL9.0PL ✓same product

Motorola MR2600 – dowolny upload firmware umożliwiający RCE

CVE-2022-34885HIGH7.2same product

An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with eleva...