Loading HuntDB...

GHSA-3fm4-36vf-4hfw

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.

Related CVEs

Key Information

GHSA ID
GHSA-3fm4-36vf-4hfw
Published
August 29, 2023 9:30 AM
Last Modified
April 4, 2024 7:15 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.