CRITICAL🇵🇱 Wersja polska

CVE-2024-23629

CVSS 9.6v3.1pub. 2024-01-26upd. 2024-11-21

An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.

🤖 AI Analysis
How it works

The vulnerability results from improper user authentication verification (CWE-287) and incorrect authorization of access to resources (CWE-863) in the device's web interface. An attacker can directly access protected URLs bypassing authentication mechanisms. As a result, it is possible to download sensitive data without the need to possess any credentials.

Impact

An attacker gains unauthorized access to protected sections of the router's web interface and can download sensitive information from the device. A high CVSS score (9.6) indicates the possibility of serious breach of confidentiality, integrity and system availability.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. Additionally, it is recommended to restrict access to the router's management interface only to trusted hosts on the local network and to disable remote access to the administrative panel if not required.

Who is affected

Motorola MR2600 (firmware) — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Motorola Mr2600

    HW
    Motorola
    all versions
  • Motorola Mr2600 Firmware

    OS
    Motorola
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-23626CRITICAL9.0PL ✓same product

Command injection w parametrze SaveSysLogParams routera Motorola MR2600

CVE-2024-23627CRITICAL9.0PL ✓same product

Command injection w parametrze SaveStaticRouteIPv4Params routera Motorola MR2600

CVE-2024-23628CRITICAL9.0PL ✓same product

Command injection w Motorola MR2600 — parametr SaveStaticRouteIPv6Params

CVE-2024-23630CRITICAL9.0PL ✓same product

Motorola MR2600 – dowolny upload firmware umożliwiający RCE

CVE-2022-34885HIGH7.2same product

An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with eleva...