Milesight CVE 脆弱性と CVE 一覧(89)

製品(CPE): — CVE 件数: 89

Milesight 脆弱性概要

Milesight 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

過去の問題は主に パス処理の欠陥 and vendor risk cross-site scripting などに関し、一部は vendor impact session compromise を招き、vendor surface production workloads and vendor surface software deployment 関連の場面に影響します。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 120 / 89 CVE 件数
«« 先頭 « 前へ 1 / 5 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-4043 An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot. [email protected] 6.1 0.19% 2025-05-07 2025-06-23
CVE-2024-36392 MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') [email protected] 6.1 0.21% 2024-06-02 2025-04-10
CVE-2024-36391 MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic [email protected] 9.1 0.04% 2024-06-02 2025-03-04
CVE-2024-36390 MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service [email protected] 7.5 0.11% 2024-06-02 2025-04-23
CVE-2024-36389 MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass [email protected] 9.8 0.07% 2024-06-02 2025-04-10
CVE-2024-36388 MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function [email protected] 10.0 0.20% 2024-06-02 2025-03-04
CVE-2024-27776 MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE [email protected] 9.8 0.57% 2024-06-02 2025-04-10
CVE-2023-47166 A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network request to trigger this vulnerability. [email protected] 8.8 0.17% 2024-05-01 2025-11-04
CVE-2023-43260 Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel. [email protected] 6.1 0.09% 2023-10-05 2024-11-21
CVE-2023-43261 An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components. [email protected] 7.5 93.06% 2023-10-04 2025-05-01
CVE-2023-25583 Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages a new vlan configuration. [email protected] 7.2 0.31% 2023-07-06 2025-11-04
CVE-2023-25582 Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages an already existing vlan configuration. [email protected] 7.2 0.31% 2023-07-06 2025-11-04
CVE-2023-25124 Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the remote_mask variables. [email protected] 7.2 0.29% 2023-07-06 2025-11-04
CVE-2023-25123 Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the remote_mask variables when action is 2. [email protected] 7.2 0.29% 2023-07-06 2025-11-04
CVE-2023-25122 Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the old_remote_subnet and the old_remote_mask variables. [email protected] 7.2 0.30% 2023-07-06 2025-11-04
CVE-2023-25121 Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_ike_profile function with the secrets_local variable. [email protected] 7.2 0.29% 2023-07-06 2025-11-04
CVE-2023-25120 Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_dmvpn function with the cisco_secret variable. [email protected] 7.2 0.30% 2023-07-06 2025-11-04
CVE-2023-25119 Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_pptp function with the remote_subnet and the remote_mask variables. [email protected] 7.2 0.30% 2023-07-06 2025-11-04
CVE-2023-25118 Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the username and the password variables. [email protected] 7.2 0.29% 2023-07-06 2025-11-04
CVE-2023-25117 Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the local_virtual_ip and the local_virtual_mask variables. [email protected] 7.2 0.29% 2023-07-06 2025-11-04
«« 先頭 « 前へ 1 / 5 次へ »
cvelogic Threat Intelligence