← Back

Motorola

motorola

91 CVEs • 105 products

Products (105)

Click to collapse
Toggle
Cx2 Firmware
cx2_firmware
M2 Firmware
m2_firmware
C1 Firmware
c1_firmware
Cx2l Firmware
cx2l_firmware
Surfboard
surfboard
Pebl U6
pebl_u6
V600
v600
Timbuktu
timbuktu
Cpei300
cpei300
Android
android
Defy Xt
defy_xt
Q14 Firmware
q14_firmware
Wr850g
wr850g
E398
e398
Motorazr
motorazr
Netoctopus
netoctopus
Razr
razr
Timbuktu Pro
timbuktu_pro
Atrix Hd
atrix_hd
Razr Hd
razr_hd
Razr M
razr_m
T008 Firmware
t008_firmware
T100 Firmware
t100_firmware
T101 Firmware
t101_firmware
T102 Firmware
t102_firmware
T103 Firmware
t103_firmware
T200 Firmware
t200_firmware
T201 Firmware
t201_firmware
T204 Firmware
t204_firmware
T205 Firmware
t205_firmware
T290 Firmware
t290_firmware
Device Help
device_help
Ready For
ready_for
Mr2600
mr2600
Mx011anm
mx011anm
Mbp853
mbp853
Sbg901
sbg901
Sbg941
sbg941
Svg1202
svg1202
M2
m2
C1
c1
Cx2
cx2
Cx2l Mwr04l
cx2l_mwr04l
C1 Mwr03
c1_mwr03
Motorola
motorola
Mh702x
mh702x
Mm1000
mm1000
T008
t008
T100
t100
T101
t101
T102
t102
T103
t103
T200
t200
T201
t201
T204
t204
T205
t205
T290
t290
Ace1000
ace1000
Moto E20
moto_e20
Cx2l
cx2l

CVEs (91)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Motorola
1Mbp853 Firmware
Nov 21, 2024
Jul 2, 2018
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one...Show more
The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one such instance, it was identified that the device was downloading what appeared to be a client certificate.Show less
2Comcast
Motorola
2Mx011anm Firmware
Xfinity Xr11 20 Firmware
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access....Show more
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access. In other words, there is no protection mechanism involving digital signatures for the firmware.Show less
1Motorola
1Mx011anm Firmware
May 13, 2026
Jul 31, 2017
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to read arbitrary files by pressing "EXIT, Down, Down, 2" on an RF4CE remote to reach th...Show more
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to read arbitrary files by pressing "EXIT, Down, Down, 2" on an RF4CE remote to reach the diagnostic display, and then launching a Remote Web Inspector script.Show less
1Motorola
1Mx011anm Firmware
May 13, 2026
Jul 31, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspector that is accessible from the public Internet.
1Motorola
1Moscad Ip Gateway Firmware
May 6, 2026
Dec 23, 2015
N/A· v4
7.5 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password.
1Motorola
1Moscad Ip Gateway Firmware
May 6, 2026
Dec 23, 2015
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.
1Motorola
1Motorola Scanner Sdk
May 6, 2026
Feb 16, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerService.exe, which allows local users to gain privileges via unspecified vectors.
1Motorola
1Motorola Scanner Sdk
May 6, 2026
Feb 16, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a crafted string to the Open method in (1) IOPOSScanner.ocx or (2) IOPOSScale.ocx.
2Google
Motorola
2Android
Defy Xt
Apr 29, 2026
Sep 25, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless allows local users to gain privileges or cause a denial of serv...Show more
Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless allows local users to gain privileges or cause a denial of service (memory corruption) by writing a long string to the /dev/socket/init_runit socket that is inconsistent with a certain length value that was previously written to this socket.Show less
2Google
Motorola
2Android
Defy Xt
Apr 29, 2026
Sep 25, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that listens for shell commands, which allows local users to gain privilege...Show more
A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that listens for shell commands, which allows local users to gain privileges by interacting with a LocalSocket object.Show less
2Motorola
Qualcomm
5Android
Atrix HdMsm8960+2 more
Apr 29, 2026
Apr 13, 2013
N/A· v4
N/A· v3
6.2 MEDIUM· v2
The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the association between a...Show more
The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the association between a certain physical-address argument and a memory region, which allows local users to unlock the bootloader by using kernel mode to perform crafted 0x9 and 0x2 SMC operations, a different vulnerability than CVE-2013-2596.Show less
2Linux
Motorola
2Android
Linux Kernel
Apr 21, 2026
Apr 13, 2013
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memor...Show more
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.Show less
1Motorola
1Surfboard Sbv6120e
Apr 29, 2026
Jun 16, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multipl...Show more
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.Show less
1Motorola
1Timbuktu Pro
Apr 23, 2026
Jun 26, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe.
1Motorola
1Cpei300
Apr 23, 2026
Feb 3, 2009
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.
1Motorola
1Cpei300
Apr 23, 2026
Feb 3, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter.
1Motorola
1Razr
Apr 23, 2026
Jun 4, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malf...Show more
Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malformed JPEG image, which triggers memory corruption.Show less
1Motorola
1Surfboard
Apr 23, 2026
Apr 28, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Mode...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Modem" value in the BUTTON_INPUT parameter to configdata.html, and (2) cause a denial of service (hard reset) via the "Reset All Defaults" value in the BUTTON_INPUT parameter to configdata.html.Show less
1Motorola
1Netoctopus
Apr 23, 2026
Jan 9, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (syst...Show more
The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.Show less
1Motorola
1Timbuktu
Apr 23, 2026
Aug 29, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in Motorola Timbuktu Pro before 8.6.5 for Windows allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via (1) a long user name and (2) certain m...Show more
Multiple buffer overflows in Motorola Timbuktu Pro before 8.6.5 for Windows allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via (1) a long user name and (2) certain malformed requests; and (3) allow remote Timbuktu servers to have an unknown impact via a malformed HELLO response, related to the Scanner component and possibly related to a malformed computer name.Show less