Motorola MR2600 SaveSysLogParams Command Injection Vulnerability
CVE-2024-23626
9CRITICAL
What is CVE-2024-23626?
A command injection vulnerability exists in the SaveSysLogParams parameter of the Motorola MR2600 router, enabling remote attackers to execute arbitrary commands. Although authentication is required to issue commands, attackers can exploit this vulnerability to bypass authentication mechanisms. This serious flaw compromises the integrity and confidentiality of networked systems connected to the affected router model, allowing unauthorized operations that could lead to further exploitation or data breaches.
Affected Version(s)
MR2600 1.0.7