Milesight develops a moderately broad portfolio of networked IoT and security devices, including industrial routers, network cameras, and device management platforms deployed across surveillance and remote-access infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting memory-safety and command-injection risks in embedded and network-facing firmware. The exposure recurs across product lines such as the UR32L industrial router and IP security cameras and centers on weakness classes including out-of-bounds writes, stack-based buffer overflows, and OS and command-injection flaws that are characteristic of C-based embedded codebases. Defenders should prioritize inventory and network segmentation of internet-exposed Milesight devices and treat firmware updates for routers and cameras as high-value patches given the direct access and lateral-movement risk these products present. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Milesight over time
Signals from CVEs in this vendor scope (89 CVEs).
89 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43261HIGH An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components. | Oct 4, 2023 | 7.5 | 72 | NO | YES |
CVE-2016-2356CRITICAL Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password. | Oct 25, 2019 | 9.8 | 32 | NO | NO |
CVE-2023-23902CRITICAL A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An att | Jul 6, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-30467CRITICAL This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Mi | Apr 28, 2023 | 9.8 | 31 | NO | NO |
CVE-2024-36389CRITICAL MileSight DeviceHub -
CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass | Jun 2, 2024 | 9.8 | 30 | NO | NO |
CVE-2016-2360CRITICAL Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations. | Oct 25, 2019 | 9.8 | 30 | NO | NO |
CVE-2016-2359CRITICAL Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotec | Oct 25, 2019 | 9.8 | 30 | NO | NO |
CVE-2016-2357CRITICAL Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory. | Oct 25, 2019 | 9.8 | 30 | NO | NO |
CVE-2024-36388CRITICAL MileSight DeviceHub -
CWE-305 Missing Authentication for Critical Function | Jun 2, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-30466CRITICAL This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism | Apr 28, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (89 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Milesight.
Media articles that mention a CVE ID that affects a product developed by Milesight — matched by CVE ID, not by vendor name.