Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · motorola

motorola

· 14 Critical

Total CVEs

95

Critical

14

Products

105

Search All CVEs →

95

Products (105)

cx211 CVEscx2 firmware11 CVEsm2 firmware10 CVEsm210 CVEsmr26007 CVEsmr2600 firmware6 CVEsmx011anm6 CVEscx2l5 CVEsc1 firmware5 CVEscx2l firmware5 CVEsace1000 firmware5 CVEsc15 CVEsace10005 CVEsmtm54004 CVEsmtm55004 CVEsmtm5500 firmware4 CVEsmtm5400 firmware4 CVEsmoscad ip gateway firmware3 CVEsrazr hd3 CVEsvigilant fixed lpr coms box3 CVEssurfboard3 CVEsmbts site controller firmware3 CVEsmbts site controller3 CVEsvigilant fixed lpr coms box firmware3 CVEspebl u63 CVEsmx011anm firmware3 CVEsq14 firmware2 CVEsandroid2 CVEsatrix hd2 CVEscpei3002 CVEscx2l mwr04l2 CVEscx2l mwr04l firmware2 CVEsdefy xt2 CVEsmbts base radio2 CVEsmbts base radio firmware2 CVEsmm10002 CVEsmm1000 firmware2 CVEsmotorola cablerouter2 CVEsmotorola scanner sdk2 CVEsq142 CVEsrazr m2 CVEstimbuktu2 CVEsv6002 CVEst290 firmware1 CVEsmoscad ip gateway1 CVEsfx9500-81324d41-us1 CVEsmoto e201 CVEsmoto e20 firmware1 CVEsmotorazr1 CVEsmotorola1 CVEsmotorola cable modem1 CVEsace ip gateway \(4600\)1 CVEsmotorola firmware1 CVEstimbuktu pro1 CVEsfx9500-41324d41-ww firmware1 CVEsfx9500-41324d41-ww1 CVEsfx9500-41324d41-us firmware1 CVEsfx9500-41324d41-us1 CVEsebts site controller firmware1 CVEsebts site controller1 CVEsebts base radio firmware1 CVEsebts base radio1 CVEsnetoctopus1 CVEse3981 CVEswr850g1 CVEsdevice help1 CVEsrazr1 CVEsc1 mwr03 firmware1 CVEsace ip gateway \(4600\) firmware1 CVEsready for1 CVEssbg9011 CVEssbg901 firmware1 CVEssbg9411 CVEssbg941 firmware1 CVEssmartphone firmware1 CVEsc1 mwr031 CVEssurfboard sbv6120e1 CVEssvg12021 CVEssvg1202 firmware1 CVEst0081 CVEst008 firmware1 CVEst1001 CVEst100 firmware1 CVEst1011 CVEst101 firmware1 CVEst1021 CVEst102 firmware1 CVEst1031 CVEst103 firmware1 CVEst2001 CVEst200 firmware1 CVEst2011 CVEst201 firmware1 CVEst2041 CVEst204 firmware1 CVEsfx9500-81324d41-ww firmware1 CVEsmbp8531 CVEsmbp853 firmware1 CVEst2051 CVEst205 firmware1 CVEsfx9500-81324d41-ww1 CVEsfx9500-81324d41-us firmware1 CVEsmh702x1 CVEsmh702x firmware1 CVEst2901 CVEs

Recent Vulnerabilities

View all 95
CVE-2022-4003LOW 2.7

A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.

CVE-2022-4002HIGH 7.2

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

CVE-2024-38281CRITICAL 9.8

An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.

CVE-2024-38280MEDIUM 4.6

An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.

CVE-2024-38279MEDIUM 4.6

The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

CVE-2024-25360MEDIUM 5.3

A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip.

CVE-2024-23630CRITICAL 9.0

An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed.

CVE-2024-23629CRITICAL 9.6

An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.

CVE-2024-23628CRITICAL 9.0

A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

CVE-2024-23627CRITICAL 9.0

A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

CVE-2024-23626CRITICAL 9.0

A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

CVE-2022-3681MEDIUM 6.5

A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.

CVE-2022-27813HIGH 8.1

Motorola MTM5000 series firmwares lack properly configured memory protection of pages shared between the OMAP-L138 ARM and DSP cores. The SoC provides two memory protection units, MPU1 and MPU2, to enforce the trust boundary between the two cores. Since both units are left unconfigured by the firmwares, an adversary with control over either core can trivially gain code execution on the other, by overwriting code located in shared RAM or DDR2 memory regions.

CVE-2022-26943HIGH 8.8

The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using a tick count register as its sole entropy source. Low boottime entropy and limited re-seeding of the pool renders the authentication challenge vulnerable to two attacks. First, due to the limited boottime pool entropy, an adversary can derive the contents of the entropy pool by an exhaustive search of possible values, based on an observed authentication challenge. Second, an adversary can use knowledge of the entropy pool to predict authentication challenges. As such, the unit is vulnerable to CVE-2022-24400.

CVE-2022-26942HIGH 8.2

The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE) modules. Two modules are used, one responsible for KVL key management and the other for TETRA cryptographic functionality. In both modules, an adversary with non-secure supervisor level code execution can exploit the issue in order to gain secure supervisor code execution within the TEE. This constitutes a full break of the TEE module, exposing the device key as well as any TETRA cryptographic keys and the confidential TETRA cryptographic primitives.

CVE-2022-26941CRITICAL 9.6

A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An attacker-controllable string is improperly handled, allowing for a write-anything-anywhere scenario. This can be leveraged to obtain arbitrary code execution inside the teds_app binary, which runs with root privileges.

CVE-2022-3407MEDIUM 4.9

I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user from dialing emergency services. This patch resolves the device's modem reset issue.

CVE-2023-23774HIGH 8.4

Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material and/or gain arbitrary code execution on the device.

CVE-2023-23773HIGH 7.2

Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.

CVE-2023-23772HIGH 7.2

Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.

CVE-2023-23771HIGH 8.4

Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

CVE-2023-23770CRITICAL 9.4

Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

CVE-2023-31531HIGH 8.8

Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter.

CVE-2023-31530HIGH 8.8

Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.

CVE-2023-31529HIGH 8.8

Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone parameter.