An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NMilesight Ur32
HWMilesightall versionsMilesight Ur32 Firmware
OSMilesight< 35.3.0.7Milesight Ur32l
HWMilesightall versionsMilesight Ur32l Firmware
OSMilesight< 35.3.0.7Milesight Ur35
HWMilesightall versionsMilesight Ur35 Firmware
OSMilesight< 35.3.0.7Milesight Ur41
HWMilesightall versionsMilesight Ur41 Firmware
OSMilesight< 35.3.0.7Milesight Ur51
HWMilesightall versionsMilesight Ur52
HWMilesightall versionsMilesight Ur55
HWMilesightall versionsMilesight Ur5x Firmware
OSMilesight< 35.3.0.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2023-23902CRITICAL9.8PL ✓same product
Buffer overflow w uhttpd Milesight UR32L umożliwiający RCE
CVE-2023-47166HIGH8.8same product
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-...
CVE-2023-22365HIGH7.2same product
An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight...
CVE-2023-22659HIGH7.2same product
An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR3...
CVE-2023-22653HIGH8.8same product
An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR3...