An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.
The vulnerability results from improper user authentication verification (CWE-287) and incorrect authorization of access to resources (CWE-863) in the device's web interface. An attacker can directly access protected URLs bypassing authentication mechanisms. As a result, it is possible to download sensitive data without the need to possess any credentials.
An attacker gains unauthorized access to protected sections of the router's web interface and can download sensitive information from the device. A high CVSS score (9.6) indicates the possibility of serious breach of confidentiality, integrity and system availability.
Patches available from the manufacturer should be applied according to references. Additionally, it is recommended to restrict access to the router's management interface only to trusted hosts on the local network and to disable remote access to the administrative panel if not required.
Motorola MR2600 (firmware) — versions indicated in the manufacturer's references
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HMotorola Mr2600
HWMotorolaall versionsMotorola Mr2600 Firmware
OSMotorolaall versions
Related vulnerabilities
Command injection w parametrze SaveSysLogParams routera Motorola MR2600
Command injection w parametrze SaveStaticRouteIPv4Params routera Motorola MR2600
Command injection w Motorola MR2600 — parametr SaveStaticRouteIPv6Params
Motorola MR2600 – dowolny upload firmware umożliwiający RCE
An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with eleva...