📦 Ur32l Firmware

by Milesight

🔍 What is Ur32l Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-23902

CRITICAL CVSS 9.8 Jul 6, 2023

A buffer overflow vulnerability in the uhttpd login functionality of Milesight UR32L routers allows remote attackers to execute arbitrary code by sending specially crafted network requests. This affec...

CVE-2023-47166

HIGH CVSS 8.8 May 1, 2024

This vulnerability allows attackers to upload arbitrary firmware to Milesight UR32L routers through the luci2-io file-import functionality. Attackers can send specially crafted network requests to ins...

CVE-2023-25118

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests. The buffer overflow occurs in th...

CVE-2023-25120

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests. The buffer overflow occurs in th...

CVE-2023-25124

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests. The buffer overflow occurs in th...

CVE-2023-25583

HIGH CVSS 7.2 Jul 6, 2023

Two OS command injection vulnerabilities in the zebra vlan_name functionality of Milesight UR32L routers allow remote attackers to execute arbitrary commands via specially crafted network requests. Th...

CVE-2023-25122

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in ...

CVE-2023-25104

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in the vtysh_ubus binary...

CVE-2023-25106

HIGH CVSS 7.2 Jul 6, 2023

Multiple buffer overflow vulnerabilities in the vtysh_ubus binary of Milesight UR32L routers allow arbitrary code execution via specially crafted HTTP requests. Attackers with high privileges can expl...

CVE-2023-25108

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in the vtysh_ubus binary...

CVE-2023-25110

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests. The buffer overflow occurs in th...

CVE-2023-25112

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers to execute arbitrary code on Milesight UR32L routers by exploiting buffer overflows in the vtysh_ubus binary. Attackers with high privileges can send ...

CVE-2023-25114

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests. The buffer overflow occurs in th...

CVE-2023-25116

HIGH CVSS 7.2 Jul 6, 2023

Multiple buffer overflow vulnerabilities in the vtysh_ubus binary of Milesight UR32L routers allow arbitrary code execution via specially crafted HTTP requests. Attackers with high privileges can expl...

CVE-2023-25092

HIGH CVSS 7.2 Jul 6, 2023

This CVE describes multiple buffer overflow vulnerabilities in the vtysh_ubus binary of Milesight UR32L routers, caused by unsafe sprintf usage. Attackers with high privileges can send specially craft...

CVE-2023-25096

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in ...

CVE-2023-25090

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in ...

CVE-2023-25098

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in ...

CVE-2023-25100

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in ...

CVE-2023-25102

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in the vtysh_ubus...

CVE-2023-25094

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests. The buffer overflow occurs in th...

CVE-2023-24519

HIGH CVSS 8.8 Jul 6, 2023

This CVE describes two OS command injection vulnerabilities in the Milesight UR32L router's vtysh_ubus toolsh_excute functionality. Attackers can execute arbitrary commands on affected devices by send...

CVE-2023-24582

HIGH CVSS 8.8 Jul 6, 2023

Two OS command injection vulnerabilities in Milesight UR32L routers allow remote attackers to execute arbitrary commands via specially crafted TCP packets. This affects UR32L routers running vulnerabl...

CVE-2023-24595

HIGH CVSS 7.2 Jul 6, 2023

This CVE describes an OS command injection vulnerability in the ys_thirdparty system_user_script functionality of Milesight UR32L routers. Attackers can execute arbitrary commands on affected devices ...

CVE-2023-25084

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests. The buffer overflow occurs in th...

CVE-2023-25082

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in ...

CVE-2023-25086

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in ...

CVE-2023-25088

HIGH CVSS 7.2 Jul 6, 2023

This vulnerability allows authenticated attackers with high privileges to execute arbitrary code on Milesight UR32L routers by sending specially crafted HTTP requests that trigger buffer overflows in ...

CVE-2023-22659

HIGH CVSS 7.2 Jul 6, 2023

This CVE describes an OS command injection vulnerability in the libzebra.so library's change_hostname function in Milesight UR32L routers. Attackers can send specially crafted network packets to execu...

CVE-2023-23550

HIGH CVSS 7.2 Jul 6, 2023

This CVE describes an OS command injection vulnerability in the Milesight UR32L router's user deletion functionality. Attackers can execute arbitrary commands on the device by sending specially crafte...

CVE-2023-24018

HIGH CVSS 8.8 Jul 6, 2023

A stack-based buffer overflow vulnerability in the libzebra.so library of Milesight UR32L routers allows authenticated attackers to execute arbitrary code via specially crafted HTTP requests. This aff...

CVE-2023-22299

HIGH CVSS 8.8 Jul 6, 2023

This CVE describes an OS command injection vulnerability in the Milesight UR32L router's vtysh_ubus _get_fw_logs functionality. Attackers can execute arbitrary commands by sending specially crafted ne...