Command Injection Vulnerability in Motorola CX2L Router
CVE-2024-45880

8HIGH

Key Information:

Vendor

Motorola

Vendor
CVE Published:
8 October 2024

What is CVE-2024-45880?

The Motorola CX2L router is susceptible to a command injection vulnerability within the SetStationSettings function. This occurs when the system improperly executes commands to configure parameters, such as MAC addresses, without filtering the input. Malicious users can exploit this weakness, injecting arbitrary commands that could compromise the router's security and functionality.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.