CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Cx2_firmware, Cx2, M2_firmware, M2, Cx2l_mwr04l_firmware, Cx2l_mwr04l, C1_mwr03_firmware, C1_mwr03, Motorola_firmware, C1_firmware
2020-08-24
N/A
5.3 MEDIUM
An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices.
Cx2_firmware, Cx2, M2_firmware, M2, Cx2l_mwr04l_firmware, Cx2l_mwr04l, C1_mwr03_firmware, C1_mwr03, Motorola_firmware, C1_firmware
2020-08-24
N/A
9.8 CRITICAL
In Motorola CX2 1.01 and M2 1.01, users can access the router's /priv_mgt.html web page to launch telnetd, as demonstrated by the 192.168.51.1 address.
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
Cx2_firmware, Cx2, M2_firmware, M2, Cx2l_mwr04l_firmware, Cx2l_mwr04l, C1_mwr03_firmware, C1_mwr03, Motorola_firmware, C1_firmware
2020-08-24
N/A
9.8 CRITICAL
An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which leads to remote code execution via shell metacharacters in a JSON value.
Zimbra Collaboration before 8.8.12 Patch 1 has persistent XSS.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none.
