CVE-2019-11319: OS Command Injection
An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which leads to remote code execution via shell metacharacters in a JSON value.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11319?
CVE-2019-11319 is a command injection vulnerability in Motorola CX2 1.01 and M2 1.01, which allows remote code execution.
What software versions are affected by CVE-2019-11319?
Motorola CX2 Firmware version 1.01 and Motorola M2 Firmware version 1.01 are affected.
How severe is CVE-2019-11319?
CVE-2019-11319 is classified as critical with a severity value of 9.8.
How can CVE-2019-11319 be exploited?
CVE-2019-11319 can be exploited by injecting malicious commands into the downloadFirmware function in hnap, leading to remote code execution.
Is there a fix for CVE-2019-11319?
At the moment, there is no known fix for CVE-2019-11319. It is recommended to update to a non-vulnerable firmware version or apply any patches provided by the vendor.