Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Motorola

First CVE: May 10, 1998Active for: 28 yearsTotal CVEs: 95
53.5
VTI Score
TOP TARGET

Motorola's vulnerability footprint spans a well-represented portfolio of enterprise mobile devices and their associated firmware, deployed across business-critical communication and management networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency to acquire public exploit code; a meaningful portion of the exposure reflects flaws in authentication and command-injection handling that are characteristic of embedded device firmware and management interfaces. The recurring weakness classes—OS command injection, command injection, and improper authentication—recur across flagship products such as the CX2, M2, and MR2600 device families and their firmware, reflecting the parsing and privilege-validation demands of enterprise-grade mobile endpoints. Defenders should prioritize Motorola device inventory and firmware updates given the severity of the recurring vulnerability classes and the challenge of managing security patches across long-lived embedded devices. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
95
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
1.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Motorola over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 10, 1998
28 years ago
Most Recent CVE
Jul 31, 2024
723 days ago

Products(105 total)

Top CVEs

Signals from CVEs in this vendor scope (95 CVEs).

95 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-2596HIGH
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows
Apr 13, 20137.863YESNO
CVE-2009-1394HIGH
Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand n
Jun 26, 20099.362NOYES
CVE-2004-1550HIGH
Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly m
Dec 31, 20047.544NOYES
CVE-2010-2307MEDIUM
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to re
Jun 16, 20105.036NOYES
CVE-2019-9121CRITICAL
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary co
Mar 7, 20199.832NONO
CVE-2019-9119CRITICAL
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary co
Mar 7, 20199.832NONO
CVE-2019-9118CRITICAL
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary co
Mar 7, 20199.832NONO
CVE-2018-20399CRITICAL
Motorola SBG901 SBG901-2.10.1.1-GA-00-581-NOSH, SBG941 SBG941-2.11.0.0-GA-07-624-NOSH, and SVG1202 SVG1202-2.1.0.0-GA-14-LTSH devices allow remote attackers to discover credentials
Dec 23, 20189.832NONO
CVE-2006-5196HIGH
The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to Secret
Oct 10, 20067.832NOYES
CVE-2020-21937CRITICAL
An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands.
Jul 21, 20219.831NONO
View all 95 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products95 CVEs
32%
46%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (8.4%)
Network51 (53.7%)
Unknown24 (25.3%)
Physical8 (8.4%)
Adjacent Network4 (4.2%)
Attack Complexity
Low70 (73.7%)
High1 (1.1%)
Unknown24 (25.3%)
User Interaction
None68 (71.6%)
Unknown24 (25.3%)
Required3 (3.2%)
Privileges Required
Low15 (15.8%)
High6 (6.3%)
None50 (52.6%)
Unknown24 (25.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (95 CVEs).

CISA KEV
1 CVE
1.1% of CVEs· 99th percentile
Metasploit
2 CVEs
2.1% of CVEs· 97th percentile
Nuclei
1 CVE
1.1% of CVEs· 95th percentile
ExploitDB
8 CVEs
8.4% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Motorola.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Motorola — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Motorola's Products

View all 5 CNAs →

Top CWEs