First published: Thu Jan 25 2024(Updated: )
A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
Credit: disclosures@exodusintel.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Motorola MR2600 | ||
Motorola MR2600 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23627 is considered a high severity command injection vulnerability.
To mitigate CVE-2024-23627, update the Motorola MR2600 firmware to the latest version provided by the manufacturer.
CVE-2024-23627 affects users of the Motorola MR2600 router running vulnerable firmware versions.
No, while CVE-2024-23627 requires authentication, the authentication mechanism can be bypassed.
Exploitation of CVE-2024-23627 can lead to remote command execution on the affected device.