CVE-2023-25089
- EPSS 0.15%
- Veröffentlicht 06.07.2023 15:15:13
- Zuletzt bearbeitet 04.11.2025 20:16:20
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges ...
CVE-2023-25081
- EPSS 0.09%
- Veröffentlicht 06.07.2023 15:15:12
- Zuletzt bearbeitet 04.11.2025 20:16:19
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges ...
CVE-2023-24519
- EPSS 0.46%
- Veröffentlicht 06.07.2023 15:15:12
- Zuletzt bearbeitet 04.11.2025 20:16:17
Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger ...
CVE-2023-24520
- EPSS 0.46%
- Veröffentlicht 06.07.2023 15:15:12
- Zuletzt bearbeitet 04.11.2025 20:16:18
Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger ...
CVE-2023-24582
- EPSS 0.15%
- Veröffentlicht 06.07.2023 15:15:12
- Zuletzt bearbeitet 04.11.2025 20:16:18
Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trig...
CVE-2023-24583
- EPSS 0.15%
- Veröffentlicht 06.07.2023 15:15:12
- Zuletzt bearbeitet 04.11.2025 20:16:18
Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trig...
CVE-2023-24595
- EPSS 0.19%
- Veröffentlicht 06.07.2023 15:15:12
- Zuletzt bearbeitet 21.11.2024 07:48:12
An OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A specially crafted series of network requests can lead to command execution. An attacker can send a sequence of requests...
CVE-2023-25082
- EPSS 0.09%
- Veröffentlicht 06.07.2023 15:15:12
- Zuletzt bearbeitet 04.11.2025 20:16:19
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges ...
CVE-2023-25083
- EPSS 0.09%
- Veröffentlicht 06.07.2023 15:15:12
- Zuletzt bearbeitet 04.11.2025 20:16:19
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges ...
CVE-2023-25084
- EPSS 0.09%
- Veröffentlicht 06.07.2023 15:15:12
- Zuletzt bearbeitet 04.11.2025 20:16:19
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges ...