Where
-Infinity
0

Systemic Pre-Installed Backdoors in Unisoc T606/T616 Enable Redundant, Zero-Click, Pre-Auth Takeover with Silent Malware Deployment in LATAM \CVSS 3.1\: 9.8 Critical \AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\ \CWE\: CWE-250, CWE-732, CWE-912, CWE-1220, CWE-276, CWE-269 \Affected\: Motorola Moto G04s, G24, G34, E24 + all Unisoc T606/T616, Android 11-13, LATAM 2024-2025 \1. Executive Summary\ "Operation Silent Rescue" identifies a \systemic attack chain affecting millions of budget Android devices in Latin America\. The vulnerability is not a single bug but a \convergence\ of: 1. \Unpatchable Hardware Flaws\: Permanent BootROM exploits CVE-2022-38694. 2. \Remote Network Vectors\: Modem RCE via rogue cell towers CVE-2025-31718. 3. \Privileged System Backdoors\: Pre-installed apps \com.spreadtrum.sgps\, \com.android.stk\, \com.dti.amx\, \com.inmobi.installer\ with exported components and \God-mode permissions\ \INSTALL\PACKAGES\, \WRITE\SECURE\SETTINGS\. This chain allows an attacker to move from \remote network access to full system root, persistent surveillance, and financial fraud without user interaction\. The risk is exacerbated in Latin America due to delayed security patches and high reliance on these devices for mobile banking. \2. The Attack Chain: Technical Breakdown\ \Phase 1: The Foundation (Hardware & Network)\ - \CVE-2022-38694 (BootROM)\: Unpatchable flaw in Unisoc T606/T616 allowing arbitrary code execution during boot. \Impact\: Permanent rootkits, bypass of Secure Boot. - \CVE-2025-31718 (Modem RCE)\: Remote code execution via malformed LTE signals. \Impact\: Over-the-air initial access \AV:N\ without user interaction. \Phase 2: The Escalation Bridges (Exported System Apps)\ Once initial access is gained, the following system apps act as \force multipliers\, escalating privileges from "modem context" to "full system control": \\Component\\ \\Package Name\\ \\Critical Flaw\\ \\Role in Chain\\ \\SGPS Middleware\\ \com.spreadtrum.sgps\ Exported Receiver. \InstallDate: 2008-12-31\. \REBOOT\ permission. \\Primary LPE Vector\\. Triggers via code \2266\. Enables \NMEA2SOCKET\. \\SIM Toolkit\\ \com.android.stk\ Exported Receiver. Runs in \com.android.phone\. \\Financial Fraud\\. Pre-auth phishing via \BootCompletedReceiver\. \\Modem Stats\\ \com.motorola.bach.modemstats\ Exported \READ\LOGS\, \MODIFY\PHONE\STATE\. \persistent=true\. \\C2 & Persistence\\. Hidden backchannel + call interception. \\Digital Turbine\\ \com.dti.amx\ \INSTALL\PACKAGES\, \WRITE\SECURE\SETTINGS\. \\Payload Delivery 1\\. Silently installs banking trojans. Disables Play Protect. \\InMobi Installer\\ \com.inmobi.installer\ Exported \InstallationService\. \QUERY\ALL\PACKAGES\. \\Payload Delivery 2\\. Public API for silent installation. \\Redundant backdoor\\. \Phase 3: The Payload (Surveillance & Fraud)\ - \Financial Theft\: Use \INSTALL\PACKAGES\ to drop banking trojans. Use \STK\ to send premium SMS or intercept 2FA codes. - \Surveillance\: Use \SGPS\ for real-time location tracking. Use \ModemStats\ for call interception and IMSI catching. - \Persistence\: Use \BootCompletedReceiver\ in STK, InMobi, DT to ensure malware survives reboots. Use BootROM to survive factory resets. \

First published (updated )
Social
reddit
Severity
5.3
EPSS
0.04%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to devicewebip.

First published (updated )
Severity
9
EPSS
0.07%
Malicious File Upload
AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed.

First published (updated )
Severity
9
EPSS
0.20%
Command Injection
AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

First published (updated )
Severity
9.6
EPSS
0.09%
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.

First published (updated )
Severity
9
EPSS
0.06%
Command Injection
AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

First published (updated )
Severity
9
EPSS
0.20%
Command Injection
AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

First published (updated )
Severity
6.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.

First published (updated )
Severity
6.8
OS Command Injection
AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communication channel being accessible by an attacker.

First published (updated )
Severity
7.8
Integer Overflow
AV:L/AC:M/Au:N/C:C/I:C/A:C

Integer overflow in the fbmmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.

1 / 2
First published (updated )
Severity
3.5
XSS
AV:N/AC:M/Au:S/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.

First published (updated )
Severity
6.8
Path Traversal
AV:N/AC:L/Au:S/C:C/I:N/A:N

Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap.

First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.

First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.

First published (updated )
Severity
7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C

The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.

First published (updated )
Severity
5.1
AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-08-01 or later includes a fix for this vulnerability.
First published (updated )
Severity
5
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-08-01 or later includes a fix for this vulnerability.
First published (updated )
Severity
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC address to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances they are leaked by a high-privilege process and can be obtained indirectly. The software build fingerprints for each confirmed vulnerable device are as follows: TCL A3X (TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAAZ:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAB3:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vAB7:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABA:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABM:user/release-keys, TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABP:user/release-keys, and TCL/A600DL/DelhiTF:11/RKQ1.201202.002/vABS:user/release-keys); TCL 10L (TCL/T770B/T1LITE:10/QKQ1.200329.002/3CJ0:user/release-keys and TCL/T770B/T1LITE:11/RKQ1.210107.001/8BIC:user/release-keys); Motorola Moto G Pure (motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-2/74844:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-7/5cde8:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-10/d67faa:user/release-keys, motorola/ellistrac/ellis:11/RRHS31.Q3-46-110-13/b4a29:user/release-keys, motorola/ellistrac/ellis:12/S3RH32.20-42-10/1c2540:user/release-keys, motorola/ellistrac/ellis:12/S3RHS32.20-42-13-2-1/6368dd:user/release-keys, motorola/ellisa/ellis:11/RRH31.Q3-46-50-2/20fec:user/release-keys, motorola/ellisvzw/ellis:11/RRH31.Q3-46-138/103bd:user/release-keys, motorola/ellisvzw/ellis:11/RRHS31.Q3-46-138-2/e5502:user/release-keys, and motorola/ellisvzw/ellis:12/S3RHS32.20-42-10-14-2/5e0b0:user/release-keys); and Motorola Moto G Power (motorola/tongag/tonga:11/RRQ31.Q3-68-16-2/e5877:user/release-keys and motorola/tongag/tonga:12/S3RQS32.20-42-10-6/f876d3:user/release-keys). This malicious app reads from the "ro.boot.wifimacaddr" system property to indirectly obtain the Wi-Fi MAC address.

First published (updated )
Severity
5
AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
6.3
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2024-03-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
5
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-09-01 or later include a fix for this vulnerability.
First published (updated )
Severity
5.1
AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later includes a fix for this vulnerability. 
First published (updated )
Severity
4.8
AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later includes a fix for this vulnerability. 
First published (updated )
Severity
4.4
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
5
AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-09-01 or later include a fix for this vulnerability.
First published (updated )
Severity
6.1
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-09-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
2.8
Path Traversal
AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )
Severity
2.8
AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.

Remedy

Update your Motorola phone to the latest software version. Software versions with a Security Patch Level of 2023-12-01 or later include a fix for this vulnerability. 
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203