Where
-Infinity
0

Systemic Pre-Installed Backdoors in Unisoc T606/T616 Enable Redundant, Zero-Click, Pre-Auth Takeover with Silent Malware Deployment in LATAM \CVSS 3.1\: 9.8 Critical \AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\ \CWE\: CWE-250, CWE-732, CWE-912, CWE-1220, CWE-276, CWE-269 \Affected\: Motorola Moto G04s, G24, G34, E24 + all Unisoc T606/T616, Android 11-13, LATAM 2024-2025 \1. Executive Summary\ "Operation Silent Rescue" identifies a \systemic attack chain affecting millions of budget Android devices in Latin America\. The vulnerability is not a single bug but a \convergence\ of: 1. \Unpatchable Hardware Flaws\: Permanent BootROM exploits CVE-2022-38694. 2. \Remote Network Vectors\: Modem RCE via rogue cell towers CVE-2025-31718. 3. \Privileged System Backdoors\: Pre-installed apps \com.spreadtrum.sgps\, \com.android.stk\, \com.dti.amx\, \com.inmobi.installer\ with exported components and \God-mode permissions\ \INSTALL\PACKAGES\, \WRITE\SECURE\SETTINGS\. This chain allows an attacker to move from \remote network access to full system root, persistent surveillance, and financial fraud without user interaction\. The risk is exacerbated in Latin America due to delayed security patches and high reliance on these devices for mobile banking. \2. The Attack Chain: Technical Breakdown\ \Phase 1: The Foundation (Hardware & Network)\ - \CVE-2022-38694 (BootROM)\: Unpatchable flaw in Unisoc T606/T616 allowing arbitrary code execution during boot. \Impact\: Permanent rootkits, bypass of Secure Boot. - \CVE-2025-31718 (Modem RCE)\: Remote code execution via malformed LTE signals. \Impact\: Over-the-air initial access \AV:N\ without user interaction. \Phase 2: The Escalation Bridges (Exported System Apps)\ Once initial access is gained, the following system apps act as \force multipliers\, escalating privileges from "modem context" to "full system control": \\Component\\ \\Package Name\\ \\Critical Flaw\\ \\Role in Chain\\ \\SGPS Middleware\\ \com.spreadtrum.sgps\ Exported Receiver. \InstallDate: 2008-12-31\. \REBOOT\ permission. \\Primary LPE Vector\\. Triggers via code \2266\. Enables \NMEA2SOCKET\. \\SIM Toolkit\\ \com.android.stk\ Exported Receiver. Runs in \com.android.phone\. \\Financial Fraud\\. Pre-auth phishing via \BootCompletedReceiver\. \\Modem Stats\\ \com.motorola.bach.modemstats\ Exported \READ\LOGS\, \MODIFY\PHONE\STATE\. \persistent=true\. \\C2 & Persistence\\. Hidden backchannel + call interception. \\Digital Turbine\\ \com.dti.amx\ \INSTALL\PACKAGES\, \WRITE\SECURE\SETTINGS\. \\Payload Delivery 1\\. Silently installs banking trojans. Disables Play Protect. \\InMobi Installer\\ \com.inmobi.installer\ Exported \InstallationService\. \QUERY\ALL\PACKAGES\. \\Payload Delivery 2\\. Public API for silent installation. \\Redundant backdoor\\. \Phase 3: The Payload (Surveillance & Fraud)\ - \Financial Theft\: Use \INSTALL\PACKAGES\ to drop banking trojans. Use \STK\ to send premium SMS or intercept 2FA codes. - \Surveillance\: Use \SGPS\ for real-time location tracking. Use \ModemStats\ for call interception and IMSI catching. - \Persistence\: Use \BootCompletedReceiver\ in STK, InMobi, DT to ensure malware survives reboots. Use BootROM to survive factory resets. \

First published (updated )
Social
reddit
Severity
8.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in the PST Service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in ForwardDaemon.exe to inject malicious code that will execute with elevated system privileges during service startup.

First published (updated )
Severity
8.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in the MotoHelperService.exe service that allows local users to potentially inject malicious code. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with elevated system privileges during service startup.

First published (updated )
Severity
5.1
AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files when transferred to a device not paired in Smart Connect.

Remedy

Update Motorola Smart Connect Android Application to version 08.0.1.011.0 (or newer).
First published (updated )
Severity
7.1
AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the software.

Remedy

Update Software Fix to version 7.3.4.13 or later. https://support.lenovo.com/us/en/downloads/ds101291-rescue-and-smart-assistant-lmsa
First published (updated )
Severity
2.8
AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2025-06-01 or later include a fix for this vulnerability.
First published (updated )
Severity
9.8
Command Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.

1 / 3
Source: NVD
First published (updated )
Severity
8
Command Injection, OS Command Injection
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the system function to execute commands for setting parameters such as MAC address without proper input filtering. This allows malicious users to inject and execute arbitrary commands.

First published (updated )
Severity
7.2
Command Injection
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

Remedy

Update Motorola Q14 Mesh Router firmware to v1.5.0.16 or later.
First published (updated )
Severity
6.5
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.

Remedy

Update Motorola Q14 Mesh Router firmware to v1.5.0.16 or later.
First published (updated )
Severity
9.8
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.

Remedy

Motorola Solutions recommends the following for each identified vulnerability: CVE-2024-38281: * Remove the hard-coded credential to access the wireless access point and disable the access point if not needed. * Set a unique SSID and password if the access point is needed. Motorola Solutions has already remediated this vulnerability for all vulnerable systems. No further actions are required by customers.
First published (updated )
Severity
7
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.

Remedy

Motorola Solutions recommends the following for each identified vulnerability: CVE-2024-38280: * Apply encryption to all Criminal Justice Information (CJI) data. * Apply full disk encryption with LUKS encryption standards and add password protection to the GRUB Bootloader. * Perform column-level encryption for sensitive data in the database. All devices shipped after May 10, 2024 are already using full disk encryption. All devices that are not able to have full disk encryption applied have had all CJI data encrypted. No further actions are required by customers.
First published (updated )
Severity
5.1
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

Remedy

Motorola Solutions recommends the following for each identified vulnerability: CVE-2024-38279: * Use secure boot implementation with an edit-resistant GRUB partition. * Additional mitigation consists in limiting the physical access to the device by following the best practices for device mounting. Edit-resistant grub partition has been remediated for all vulnerable systems. Motorola Solutions will release a secure boot implementation in Fall 2024. All customers will receive the update through OTA (over the air) mechanisms. No further actions are required by customers.
First published (updated )
Severity
2.8
EPSS
0.04%
AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-09-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
2.8
EPSS
0.04%
AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
6.3
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2024-03-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later includes a fix for this vulnerability. 
First published (updated )
Severity
4.4
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-09-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
5.1
AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later includes a fix for this vulnerability. 
First published (updated )
Severity
2.8
Path Traversal
AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
2.8
AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
4.4
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
4.8
AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later includes a fix for this vulnerability. 
First published (updated )
Severity
5
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-09-01 or later include a fix for this vulnerability.
First published (updated )
Severity
5
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-09-01 or later include a fix for this vulnerability.
First published (updated )
Severity
6.1
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-09-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
5
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
2.8
AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
5
AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC address to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances they are leaked by a high-privilege process and can be obtained indirectly. The software build fingerprints for each confirmed vulnerable device are as follows: TCL A3X (TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAAZ:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAB3:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAB7:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABA:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABM:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABP:user/release-keys, and TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABS:user/release-keys); TCL 10L (TCL/T770B/T1LITE:10/QKQ1.200329.002/3CJ0:user/release-keys and TCL/T770B/T1LITE:11/RKQ1.210107.001/8BIC:user/release-keys); Motorola Moto G Pure (motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-2/74844:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-7/5cde8:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-10/d67faa:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-13/b4a29:user/release-keys, motorola/ellistrac/ellis:12/S3RH32.20-42-10/1c2540:user/release-keys, motorola/ellistrac/ellis:12/S3RHS32.20-42-13-2-1/6368dd:user/release-keys, motorola/ellisa/ellis:11/RRH31.Q3-46-50-2/20fec:user/release-keys, motorola/ellisvzw/ellis:11/RRH31.Q3-46-138/103bd:user/release-keys, motorola/ellisvzw/ellis:11/RRHS31.Q3-46-138-2/e5502:user/release-keys, and motorola/ellisvzw/ellis:12/S3RHS32.20-42-10-14-2/5e0b0:user/release-keys); and Motorola Moto G Power (motorola/tongag/tonga:11/RRQ31.Q3-68-16-2/e5877:user/release-keys and motorola/tongag/tonga:12/S3RQS32.20-42-10-6/f876d3:user/release-keys). This malicious app reads from the "ro.boot.wifimacaddr" system property to indirectly obtain the Wi-Fi MAC address.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203