See how motorola compares to other vendors in security performance
Systemic Pre-Installed Backdoors in Unisoc T606/T616 Enable Redundant, Zero-Click, Pre-Auth Takeover with Silent Malware Deployment in LATAM \CVSS 3.1\: 9.8 Critical \AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\ \CWE\: CWE-250, CWE-732, CWE-912, CWE-1220, CWE-276, CWE-269 \Affected\: Motorola Moto G04s, G24, G34, E24 + all Unisoc T606/T616, Android 11-13, LATAM 2024-2025 \1. Executive Summary\ "Operation Silent Rescue" identifies a \systemic attack chain affecting millions of budget Android devices in Latin America\. The vulnerability is not a single bug but a \convergence\ of: 1. \Unpatchable Hardware Flaws\: Permanent BootROM exploits CVE-2022-38694. 2. \Remote Network Vectors\: Modem RCE via rogue cell towers CVE-2025-31718. 3. \Privileged System Backdoors\: Pre-installed apps \com.spreadtrum.sgps\, \com.android.stk\, \com.dti.amx\, \com.inmobi.installer\ with exported components and \God-mode permissions\ \INSTALL\PACKAGES\, \WRITE\SECURE\SETTINGS\. This chain allows an attacker to move from \remote network access to full system root, persistent surveillance, and financial fraud without user interaction\. The risk is exacerbated in Latin America due to delayed security patches and high reliance on these devices for mobile banking. \2. The Attack Chain: Technical Breakdown\ \Phase 1: The Foundation (Hardware & Network)\ - \CVE-2022-38694 (BootROM)\: Unpatchable flaw in Unisoc T606/T616 allowing arbitrary code execution during boot. \Impact\: Permanent rootkits, bypass of Secure Boot. - \CVE-2025-31718 (Modem RCE)\: Remote code execution via malformed LTE signals. \Impact\: Over-the-air initial access \AV:N\ without user interaction. \Phase 2: The Escalation Bridges (Exported System Apps)\ Once initial access is gained, the following system apps act as \force multipliers\, escalating privileges from "modem context" to "full system control": \\Component\\ \\Package Name\\ \\Critical Flaw\\ \\Role in Chain\\ \\SGPS Middleware\\ \com.spreadtrum.sgps\ Exported Receiver. \InstallDate: 2008-12-31\. \REBOOT\ permission. \\Primary LPE Vector\\. Triggers via code \2266\. Enables \NMEA2SOCKET\. \\SIM Toolkit\\ \com.android.stk\ Exported Receiver. Runs in \com.android.phone\. \\Financial Fraud\\. Pre-auth phishing via \BootCompletedReceiver\. \\Modem Stats\\ \com.motorola.bach.modemstats\ Exported \READ\LOGS\, \MODIFY\PHONE\STATE\. \persistent=true\. \\C2 & Persistence\\. Hidden backchannel + call interception. \\Digital Turbine\\ \com.dti.amx\ \INSTALL\PACKAGES\, \WRITE\SECURE\SETTINGS\. \\Payload Delivery 1\\. Silently installs banking trojans. Disables Play Protect. \\InMobi Installer\\ \com.inmobi.installer\ Exported \InstallationService\. \QUERY\ALL\PACKAGES\. \\Payload Delivery 2\\. Public API for silent installation. \\Redundant backdoor\\. \Phase 3: The Payload (Surveillance & Fraud)\ - \Financial Theft\: Use \INSTALL\PACKAGES\ to drop banking trojans. Use \STK\ to send premium SMS or intercept 2FA codes. - \Surveillance\: Use \SGPS\ for real-time location tracking. Use \ModemStats\ for call interception and IMSI catching. - \Persistence\: Use \BootCompletedReceiver\ in STK, InMobi, DT to ensure malware survives reboots. Use BootROM to survive factory resets. \
A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to devicewebip.
An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed.
A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.
A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.
A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.
The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communication channel being accessible by an attacker.
Integer overflow in the fbmmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.
Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.
Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter.
Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap.
A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.
The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.
The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.
An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.
An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.
An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC address to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances they are leaked by a high-privilege process and can be obtained indirectly. The software build fingerprints for each confirmed vulnerable device are as follows: TCL A3X (TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAAZ:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAB3:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAB7:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABA:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABM:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABP:user/release-keys, and TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABS:user/release-keys); TCL 10L (TCL/T770B/T1LITE:10/QKQ1.200329.002/3CJ0:user/release-keys and TCL/T770B/T1LITE:11/RKQ1.210107.001/8BIC:user/release-keys); Motorola Moto G Pure (motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-2/74844:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-7/5cde8:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-10/d67faa:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-13/b4a29:user/release-keys, motorola/ellistrac/ellis:12/S3RH32.20-42-10/1c2540:user/release-keys, motorola/ellistrac/ellis:12/S3RHS32.20-42-13-2-1/6368dd:user/release-keys, motorola/ellisa/ellis:11/RRH31.Q3-46-50-2/20fec:user/release-keys, motorola/ellisvzw/ellis:11/RRH31.Q3-46-138/103bd:user/release-keys, motorola/ellisvzw/ellis:11/RRHS31.Q3-46-138-2/e5502:user/release-keys, and motorola/ellisvzw/ellis:12/S3RHS32.20-42-10-14-2/5e0b0:user/release-keys); and Motorola Moto G Power (motorola/tongag/tonga:11/RRQ31.Q3-68-16-2/e5877:user/release-keys and motorola/tongag/tonga:12/S3RQS32.20-42-10-6/f876d3:user/release-keys). This malicious app reads from the "ro.boot.wifimacaddr" system property to indirectly obtain the Wi-Fi MAC address.
An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.
A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.
An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices.
A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission.
An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.
An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.
A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.
A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers.
A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files.
An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.