Impact
The vulnerability allows a malicious third‑party Android application to manipulate the Smart Connect dashboard UI. When combined with a phishing attack, the manipulation can grant the attacker elevated privileges within the device’s system. This issue stems from a missing authorization control, as reflected by CWE-862, enabling unauthorized actions through the UI layer.
Affected Systems
Motorola Smart Connect Application is affected. Devices running any version prior to the 9.03.00.61 release are at risk. The impact specifically targets the Android-based Smart Connect dashboard used for managing related motorola devices.
Risk and Exploitability
The CVSS score of 7.3 indicates substantial severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to install a third‑party app that can manipulate the UI, typically through local installation. If a user falls for a phishing incentive, the attacker may leverage the manipulated UI to gain higher system privileges. The attack vector is likely local, requiring physical or credential access to the device to install the malicious application.
OpenCVE Enrichment