← Back

Milesight

milesight

89 CVEs • 65 products

Products (65)

Click to collapse
Toggle
Devicehub
devicehub
Milesightvpn
milesightvpn
Ur32 Firmware
ur32_firmware
Ur35 Firmware
ur35_firmware
Ur41 Firmware
ur41_firmware
Ur5x Firmware
ur5x_firmware
Ur51 Firmware
ur51_firmware
Ur52 Firmware
ur52_firmware
Ur55 Firmware
ur55_firmware
Ms N5008 Uc
ms-n5008-uc
Ms N1008 Unc
ms-n1008-unc
Ms N1008 Uc
ms-n1008-uc
Ms N1004 Uc
ms-n1004-uc
Ms N5016 E
ms-n5016-e
Ms N5008 E
ms-n5008-e
Ms N7016 Uh
ms-n7016-uh
Ms N7032 Uh
ms-n7032-uh
Ms N8064 Uh
ms-n8064-uh
Ms N8032 Uh
ms-n8032-uh
Ms N1004 Upc
ms-n1004-upc
Ms N1008 Upc
ms-n1008-upc
Ms N1008 Unpc
ms-n1008-unpc
Ms N5008 Upc
ms-n5008-upc
Ms N5016 Pe
ms-n5016-pe
Ms N5008 Pe
ms-n5008-pe
Ms N7016 Uph
ms-n7016-uph
Ms N7032 Uph
ms-n7032-uph
Ms N7048 Uph
ms-n7048-uph
Ncr/camera
ncr/camera
Ur32l
ur32l
Ur51
ur51
Ur52
ur52
Ur55
ur55
Ur32
ur32
Ur35
ur35
Ur41
ur41
Ug65 868m Ea
ug65-868m-ea

CVEs (89)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Milesight
1Ug65 868m Ea Firmware
Jun 17, 2026
May 7, 2025
6.1 MEDIUM· v4
6.8 MEDIUM· v3
N/A· v2
An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot.
1Milesight
1Devicehub
Jun 17, 2026
Jun 2, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Milesight
1Devicehub
Jun 17, 2026
Jun 2, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
1Milesight
1Devicehub
Jun 17, 2026
Jun 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service
1Milesight
1Devicehub
Jun 17, 2026
Jun 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
1Milesight
1Devicehub
Jun 17, 2026
Jun 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
1Milesight
1Devicehub
Jun 17, 2026
Jun 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE
1Milesight
1Ur32l Firmware
Jun 17, 2026
May 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network...Show more
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network request to trigger this vulnerability.Show less
1Milesight
7Ur32 Firmware
Ur32l FirmwareUr35 Firmware+4 more
Jun 17, 2026
Oct 5, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.
1Milesight
5Ur32 Firmware
Ur32l FirmwareUr35 Firmware+2 more
Jul 9, 2026
Oct 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
1Milesight
1Ur32l Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request...Show more
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages a new vlan configuration.Show less
1Milesight
1Ur32l Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request...Show more
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages an already existing vlan configuration.Show less
1Milesight
1Ur32l Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An...Show more
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the remote_mask variables.Show less
1Milesight
1Ur32l Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An...Show more
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the remote_subnet and the remote_mask variables when action is 2.Show less
1Milesight
1Ur32l Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An...Show more
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the old_remote_subnet and the old_remote_mask variables.Show less
1Milesight
1Ur32l Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An...Show more
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_ike_profile function with the secrets_local variable.Show less
1Milesight
1Ur32l Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An...Show more
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_dmvpn function with the cisco_secret variable.Show less
1Milesight
1Ur32l Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An...Show more
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_pptp function with the remote_subnet and the remote_mask variables.Show less
1Milesight
1Ur32l Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An...Show more
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the username and the password variables.Show less
1Milesight
1Ur32l Firmware
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An...Show more
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the local_virtual_ip and the local_virtual_mask variables.Show less