First published: Thu Jan 25 2024(Updated: )
A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
Credit: disclosures@exodusintel.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Motorola Mr2600 Firmware | ||
Motorola MR2600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23628 is classified as a critical command injection vulnerability.
To mitigate CVE-2024-23628, apply the latest firmware updates provided by Motorola.
CVE-2024-23628 specifically affects the Motorola MR2600 router.
CVE-2024-23628 requires authentication; however, it can be bypassed by attackers.
Exploiting CVE-2024-23628 could allow a remote attacker to execute arbitrary commands on the affected device.