An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which leads to remote code execution via shell metacharacters in a JSON value.
References
Link | Resource |
---|---|
https://github.com/TeamSeri0us/pocs/blob/master/iot/motorola.pdf | Exploit Third Party Advisory |
Information
Published : 2019-04-18 10:29
Updated : 2020-08-24 10:37
NVD link : CVE-2019-11319
Mitre link : CVE-2019-11319
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
motorola
- m2
- cx2_firmware
- m2_firmware
- cx2