A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to devicewebip.
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the systemtimetimezone parameter.
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomographypingnumber parameter.
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqosprioritydevices parameter.
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroutelist parameter.
An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a device hang.
On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8010 and UDP port 8080. It is caused by snprintf and inappropriate length handling.