彙總 Milesight 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
歷史漏洞主要涉及 路徑處理缺陷與跨站腳本 等問題,部分漏洞可能導致 工作階段劫持,並影響 生產負載與軟體部署 相關場景。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2025-4043 | An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot. | [email protected] | 6.1 | 0.19% | 2025-05-07 | 2025-06-23 |
| CVE-2024-36392 | MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] | 6.1 | 0.21% | 2024-06-02 | 2025-04-10 |
| CVE-2024-36391 | MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic | [email protected] | 9.1 | 0.04% | 2024-06-02 | 2025-03-04 |
| CVE-2024-36390 | MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service | [email protected] | 7.5 | 0.11% | 2024-06-02 | 2025-04-23 |
| CVE-2024-36389 | MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass | [email protected] | 9.8 | 0.07% | 2024-06-02 | 2025-04-10 |
| CVE-2024-36388 | MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function | [email protected] | 10.0 | 0.20% | 2024-06-02 | 2025-03-04 |
| CVE-2024-27776 | MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE | [email protected] | 9.8 | 0.57% | 2024-06-02 | 2025-04-10 |
| CVE-2023-47166 | A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network request to trigger this vulnerability. | [email protected] | 8.8 | 0.17% | 2024-05-01 | 2025-11-04 |
| CVE-2023-43260 | Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel. | [email protected] | 6.1 | 0.09% | 2023-10-05 | 2024-11-21 |
| CVE-2023-43261 | An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components. | [email protected] | 7.5 | 93.06% | 2023-10-04 | 2025-05-01 |
| CVE-2023-25583 | Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages a new vlan configuration. | [email protected] | 7.2 | 0.31% | 2023-07-06 | 2025-11-04 |
| CVE-2023-25582 | Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages an already existing vlan configuration. | [email protected] | 7.2 | 0.31% | 2023-07-06 | 2025-11-04 |
| CVE-2023-25124 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the remote_mask variables. | [email protected] | 7.2 | 0.29% | 2023-07-06 | 2025-11-04 |
| CVE-2023-25123 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the remote_mask variables when action is 2. | [email protected] | 7.2 | 0.29% | 2023-07-06 | 2025-11-04 |
| CVE-2023-25122 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the old_remote_subnet and the old_remote_mask variables. | [email protected] | 7.2 | 0.30% | 2023-07-06 | 2025-11-04 |
| CVE-2023-25121 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_ike_profile function with the secrets_local variable. | [email protected] | 7.2 | 0.29% | 2023-07-06 | 2025-11-04 |
| CVE-2023-25120 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_dmvpn function with the cisco_secret variable. | [email protected] | 7.2 | 0.30% | 2023-07-06 | 2025-11-04 |
| CVE-2023-25119 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_pptp function with the remote_subnet and the remote_mask variables. | [email protected] | 7.2 | 0.30% | 2023-07-06 | 2025-11-04 |
| CVE-2023-25118 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the username and the password variables. | [email protected] | 7.2 | 0.29% | 2023-07-06 | 2025-11-04 |
| CVE-2023-25117 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the local_virtual_ip and the local_virtual_mask variables. | [email protected] | 7.2 | 0.29% | 2023-07-06 | 2025-11-04 |