Hackers Can Exploit Motorola MR2600 Firmware Update Process to Gain Code Execution
ID: 0d1ec347-e4c9-56a6-aaa0-d2eb310946e0
STIX ID: report--0d1ec347-e4c9-56a6-aaa0-d2eb310946e0
Feed Name: cybersecurityNews.com
A newly disclosed unauthenticated remote code execution vulnerability in Motorola MR2600 routers lets attackers upload a crafted SEAMA firmware image by bypassing multipart upload validation and an authentication check on the firmware validation SOAP endpoint; because firmware flashing lacks cryptographic signing the malicious image can be validated and flashed, producing persistent attacker-controlled firmware. The issue affects end-of-life devices, researcher data shows some MR2600s with remote administration exposed, and vendor response was unclear; recommended mitigations include disabling remote management, restricting admin access, or replacing affected devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
