See how motorola compares to other vendors in security performance
Systemic Pre-Installed Backdoors in Unisoc T606/T616 Enable Redundant, Zero-Click, Pre-Auth Takeover with Silent Malware Deployment in LATAM \CVSS 3.1\: 9.8 Critical \AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\ \CWE\: CWE-250, CWE-732, CWE-912, CWE-1220, CWE-276, CWE-269 \Affected\: Motorola Moto G04s, G24, G34, E24 + all Unisoc T606/T616, Android 11-13, LATAM 2024-2025 \1. Executive Summary\ "Operation Silent Rescue" identifies a \systemic attack chain affecting millions of budget Android devices in Latin America\. The vulnerability is not a single bug but a \convergence\ of: 1. \Unpatchable Hardware Flaws\: Permanent BootROM exploits CVE-2022-38694. 2. \Remote Network Vectors\: Modem RCE via rogue cell towers CVE-2025-31718. 3. \Privileged System Backdoors\: Pre-installed apps \com.spreadtrum.sgps\, \com.android.stk\, \com.dti.amx\, \com.inmobi.installer\ with exported components and \God-mode permissions\ \INSTALL\PACKAGES\, \WRITE\SECURE\SETTINGS\. This chain allows an attacker to move from \remote network access to full system root, persistent surveillance, and financial fraud without user interaction\. The risk is exacerbated in Latin America due to delayed security patches and high reliance on these devices for mobile banking. \2. The Attack Chain: Technical Breakdown\ \Phase 1: The Foundation (Hardware & Network)\ - \CVE-2022-38694 (BootROM)\: Unpatchable flaw in Unisoc T606/T616 allowing arbitrary code execution during boot. \Impact\: Permanent rootkits, bypass of Secure Boot. - \CVE-2025-31718 (Modem RCE)\: Remote code execution via malformed LTE signals. \Impact\: Over-the-air initial access \AV:N\ without user interaction. \Phase 2: The Escalation Bridges (Exported System Apps)\ Once initial access is gained, the following system apps act as \force multipliers\, escalating privileges from "modem context" to "full system control": \\Component\\ \\Package Name\\ \\Critical Flaw\\ \\Role in Chain\\ \\SGPS Middleware\\ \com.spreadtrum.sgps\ Exported Receiver. \InstallDate: 2008-12-31\. \REBOOT\ permission. \\Primary LPE Vector\\. Triggers via code \2266\. Enables \NMEA2SOCKET\. \\SIM Toolkit\\ \com.android.stk\ Exported Receiver. Runs in \com.android.phone\. \\Financial Fraud\\. Pre-auth phishing via \BootCompletedReceiver\. \\Modem Stats\\ \com.motorola.bach.modemstats\ Exported \READ\LOGS\, \MODIFY\PHONE\STATE\. \persistent=true\. \\C2 & Persistence\\. Hidden backchannel + call interception. \\Digital Turbine\\ \com.dti.amx\ \INSTALL\PACKAGES\, \WRITE\SECURE\SETTINGS\. \\Payload Delivery 1\\. Silently installs banking trojans. Disables Play Protect. \\InMobi Installer\\ \com.inmobi.installer\ Exported \InstallationService\. \QUERY\ALL\PACKAGES\. \\Payload Delivery 2\\. Public API for silent installation. \\Redundant backdoor\\. \Phase 3: The Payload (Surveillance & Fraud)\ - \Financial Theft\: Use \INSTALL\PACKAGES\ to drop banking trojans. Use \STK\ to send premium SMS or intercept 2FA codes. - \Surveillance\: Use \SGPS\ for real-time location tracking. Use \ModemStats\ for call interception and IMSI catching. - \Persistence\: Use \BootCompletedReceiver\ in STK, InMobi, DT to ensure malware survives reboots. Use BootROM to survive factory resets. \
Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in the PST Service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in ForwardDaemon.exe to inject malicious code that will execute with elevated system privileges during service startup.
Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in the MotoHelperService.exe service that allows local users to potentially inject malicious code. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with elevated system privileges during service startup.
A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files when transferred to a device not paired in Smart Connect.
A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the software.
An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access.
A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.
A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the system function to execute commands for setting parameters such as MAC address without proper input filtering. This allows malicious users to inject and execute arbitrary commands.
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.
The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data.
An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.
A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.
An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization.
An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.
A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission.
A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files.
An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data.
An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.
An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.
A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.
An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices.
A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers.
An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs.
An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.
An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.
An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC address to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances they are leaked by a high-privilege process and can be obtained indirectly. The software build fingerprints for each confirmed vulnerable device are as follows: TCL A3X (TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAAZ:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAB3:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAB7:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABA:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABM:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABP:user/release-keys, and TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABS:user/release-keys); TCL 10L (TCL/T770B/T1LITE:10/QKQ1.200329.002/3CJ0:user/release-keys and TCL/T770B/T1LITE:11/RKQ1.210107.001/8BIC:user/release-keys); Motorola Moto G Pure (motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-2/74844:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-7/5cde8:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-10/d67faa:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-13/b4a29:user/release-keys, motorola/ellistrac/ellis:12/S3RH32.20-42-10/1c2540:user/release-keys, motorola/ellistrac/ellis:12/S3RHS32.20-42-13-2-1/6368dd:user/release-keys, motorola/ellisa/ellis:11/RRH31.Q3-46-50-2/20fec:user/release-keys, motorola/ellisvzw/ellis:11/RRH31.Q3-46-138/103bd:user/release-keys, motorola/ellisvzw/ellis:11/RRHS31.Q3-46-138-2/e5502:user/release-keys, and motorola/ellisvzw/ellis:12/S3RHS32.20-42-10-14-2/5e0b0:user/release-keys); and Motorola Moto G Power (motorola/tongag/tonga:11/RRQ31.Q3-68-16-2/e5877:user/release-keys and motorola/tongag/tonga:12/S3RQS32.20-42-10-6/f876d3:user/release-keys). This malicious app reads from the "ro.boot.wifimacaddr" system property to indirectly obtain the Wi-Fi MAC address.