Motorola's vulnerability footprint spans a well-represented portfolio of enterprise mobile devices and their associated firmware, deployed across business-critical communication and management networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency to acquire public exploit code; a meaningful portion of the exposure reflects flaws in authentication and command-injection handling that are characteristic of embedded device firmware and management interfaces. The recurring weakness classes—OS command injection, command injection, and improper authentication—recur across flagship products such as the CX2, M2, and MR2600 device families and their firmware, reflecting the parsing and privilege-validation demands of enterprise-grade mobile endpoints. Defenders should prioritize Motorola device inventory and firmware updates given the severity of the recurring vulnerability classes and the challenge of managing security patches across long-lived embedded devices. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Motorola over time
Signals from CVEs in this vendor scope (95 CVEs).
95 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2596HIGH Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows | Apr 13, 2013 | 7.8 | 63 | YES | NO |
CVE-2009-1394HIGH Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand n | Jun 26, 2009 | 9.3 | 62 | NO | YES |
CVE-2004-1550HIGH Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly m | Dec 31, 2004 | 7.5 | 44 | NO | YES |
CVE-2010-2307MEDIUM Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to re | Jun 16, 2010 | 5.0 | 36 | NO | YES |
CVE-2019-9121CRITICAL An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary co | Mar 7, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-9119CRITICAL An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary co | Mar 7, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-9118CRITICAL An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary co | Mar 7, 2019 | 9.8 | 32 | NO | NO |
CVE-2018-20399CRITICAL Motorola SBG901 SBG901-2.10.1.1-GA-00-581-NOSH, SBG941 SBG941-2.11.0.0-GA-07-624-NOSH, and SVG1202 SVG1202-2.1.0.0-GA-14-LTSH devices allow remote attackers to discover credentials | Dec 23, 2018 | 9.8 | 32 | NO | NO |
CVE-2006-5196HIGH The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to Secret | Oct 10, 2006 | 7.8 | 32 | NO | YES |
CVE-2020-21937CRITICAL An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands. | Jul 21, 2021 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (95 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Motorola.
Media articles that mention a CVE ID that affects a product developed by Motorola — matched by CVE ID, not by vendor name.