A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

Subscriptions

Vendors Products
Motorola Subscribe
Q14 Firmware Subscribe
Q14 Mesh Router Firmware Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-51383 A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
Fixes

Solution

Update Motorola Q14 Mesh Router firmware to v1.5.0.16 or later.


Workaround

No workaround given by the vendor.

History

Tue, 13 Aug 2024 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Motorola q14
Motorola q14 Firmware
Weaknesses CWE-77
CPEs cpe:2.3:h:motorola:q14:-:*:*:*:*:*:*:*
cpe:2.3:o:motorola:q14_firmware:*:*:*:*:*:*:*:*
Vendors & Products Motorola q14
Motorola q14 Firmware

Tue, 06 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Motorola
Motorola q14 Mesh Router Firmware
CPEs cpe:2.3:o:motorola:q14_mesh_router_firmware:*:*:*:*:*:*:*:*
Vendors & Products Motorola
Motorola q14 Mesh Router Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-06T19:28:56.303Z

Reserved: 2022-11-15T15:22:02.878Z

Link: CVE-2022-4002

cve-icon Vulnrichment

Updated: 2024-08-06T19:28:45.416Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-31T21:15:14.627

Modified: 2024-08-13T15:23:51.097

Link: CVE-2022-4002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses