CVE-2022-26941

A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An attacker-controllable string is improperly handled, allowing for a write-anything-anywhere scenario. This can be leveraged to obtain arbitrary code execution inside the teds_app binary, which runs with root privileges.
References
Link Resource
https://tetraburst.com/ Technical Description
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:motorola:mtm5500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mtm5500:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:motorola:mtm5400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mtm5400:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-10-19 10:15

Updated : 2023-11-07 03:45


NVD link : CVE-2022-26941

Mitre link : CVE-2022-26941

CVE.ORG link : CVE-2022-26941


JSON object : View

Products Affected

motorola

  • mtm5500_firmware
  • mtm5400
  • mtm5500
  • mtm5400_firmware
CWE
CWE-134

Use of Externally-Controlled Format String