CVE-2023-43261 is an information disclosure vulnerability affecting several Milesight UR series industrial routers (UR5X, UR32L, UR32, UR35, UR41) prior to version v35.3.0.7. This flaw allows unauthenticated attackers to remotely access sensitive router components, posing a significant risk. Rated with a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to a high impact on confidentiality. Its high EPSS score and FAUCET Risk Score of 99/100 indicate a strong likelihood of exploitation. While not yet listed in CISA's KEV catalog, there are public Nuclei templates available for detection, and community discussion suggests real-world interest. Media coverage also indicates potential exploitation in attacks, highlighting the urgency of patching affected devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 35.3.0.7CPE matchmatch criteria | cpe:2.3:o:milesight:ur5x_firmware:*:*:*:*:*:*:*:* | ||
< 35.3.0.7CPE matchmatch criteria | cpe:2.3:o:milesight:ur32l_firmware:*:*:*:*:*:*:*:* | ||
< 35.3.0.7CPE matchmatch criteria | cpe:2.3:o:milesight:ur32_firmware:*:*:*:*:*:*:*:* | ||
< 35.3.0.7CPE matchmatch criteria | cpe:2.3:o:milesight:ur35_firmware:*:*:*:*:*:*:*:* | ||
< 35.3.0.7CPE matchmatch criteria | cpe:2.3:o:milesight:ur41_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.