CVE-2019-9121: OS Command Injection
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetSmartQoSSettings API function, as demonstrated by shell metacharacters in the smartqosprioritydevices field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9121?
CVE-2019-9121 is a Command Injection vulnerability found on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively.
What is the severity of CVE-2019-9121?
The severity of CVE-2019-9121 is critical with a CVSS score of 9.8.
How does CVE-2019-9121 affect Motorola C1 and M2 devices?
CVE-2019-9121 allows a remote attacker to execute arbitrary code and get a root shell on Motorola C1 and M2 devices.
How can I fix CVE-2019-9121?
To fix CVE-2019-9121, update your Motorola C1 firmware to version 1.01 and M2 firmware to version 1.07.
Where can I find more information about CVE-2019-9121?
You can find more information about CVE-2019-9121 at the following reference: [link](https://github.com/lieanu/vuls/blob/master/motorola/M2_C1/SetSmartQoSSettings.md)