Description
A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An attacker-controllable string is improperly handled, allowing for a write-anything-anywhere scenario. This can be leveraged to obtain arbitrary code execution inside the teds_app binary, which runs with root privileges.
Published: 2023-10-19
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-31486 A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An attacker-controllable string is improperly handled, allowing for a write-anything-anywhere scenario. This can be leveraged to obtain arbitrary code execution inside the teds_app binary, which runs with root privileges.
References
Link Providers
https://tetraburst.com/ cve-icon cve-icon
History

Wed, 25 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Motorola mobile Radio
CPEs cpe:2.3:a:motorola:mobile_radio:*:*:*:*:*:*:*:*
Vendors & Products Motorola mobile Radio
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Motorola Mobile Radio Mtm5400 Mtm5400 Firmware Mtm5500 Mtm5500 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC-NL

Published:

Updated: 2024-09-12T20:28:58.903Z

Reserved: 2022-03-11T22:19:24.847Z

Link: CVE-2022-26941

cve-icon Vulnrichment

Updated: 2024-08-03T05:18:38.375Z

cve-icon NVD

Status : Modified

Published: 2023-10-19T10:15:09.860

Modified: 2024-11-21T06:54:50.533

Link: CVE-2022-26941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses