← Back

Ur32l Firmware

ur32l_firmware

Vendor: Milesight • 66 CVEs

CVEs (66)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Milesight
1Ur32l Firmware
Nov 21, 2024
Jul 6, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-...Show more
A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.Show less
1Milesight
1Ur32l Firmware
Nov 21, 2024
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequen...Show more
An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Milesight
1Ur32l Firmware
Nov 21, 2024
Jul 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An authenticated attacker can se...Show more
An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An authenticated attacker can send an HTTP request to trigger this vulnerability.Show less
1Milesight
1Ur32l Firmware
Nov 21, 2024
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32.3.0.5. A specially crafted set of network packets can lead to command execution. An attacker can se...Show more
An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32.3.0.5. A specially crafted set of network packets can lead to command execution. An attacker can send a network request to trigger this vulnerability.Show less
1Milesight
1Ur32l Firmware
Nov 21, 2024
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence o...Show more
An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Milesight
1Ur32l Firmware
Nov 21, 2024
Jul 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network re...Show more
An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.Show less