Vulnerability Description
An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Motorola | Cx2 Firmware | 1.01 |
| Motorola | Cx2 | - |
| Motorola | M2 Firmware | 1.01 |
| Motorola | M2 | - |
Related Weaknesses (CWE)
References
- https://github.com/TeamSeri0us/pocs/blob/master/iot/motorola.pdfExploitThird Party Advisory
- https://github.com/TeamSeri0us/pocs/blob/master/iot/motorola.pdfExploitThird Party Advisory
FAQ
What is CVE-2019-11321?
CVE-2019-11321 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC address...
How severe is CVE-2019-11321?
CVE-2019-11321 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11321?
Check the references section above for vendor advisories and patch information. Affected products include: Motorola Cx2 Firmware, Motorola Cx2, Motorola M2 Firmware, Motorola M2.