Ur32l
Vendor:
First CVE: Jul 6, 2023 · Active for 3 years
66
Total CVEs
More Total CVEs than 98% of tracked products
33.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ur32l over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 6, 2023
3 years ago
Most Recent CVE
May 1, 2024
817 days ago
CVE Severity & Scoring
Ur32l66 CVEs
95%
All CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network66 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low64 (97.0%)
High2 (3.0%)
Unknown0 (0.0%)
User Interaction
None63 (95.5%)
Unknown0 (0.0%)
Required3 (4.5%)
Privileges Required
Low7 (10.6%)
High51 (77.3%)
None8 (12.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (66 CVEs).
66 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43261HIGH An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components. | Oct 4, 2023 | 7.5 | 72 | NO | YES |
CVE-2023-23902CRITICAL A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An att | Jul 6, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-22653HIGH An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command exe | Jul 6, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-24520HIGH Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to | Jul 6, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-24519HIGH Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to | Jul 6, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-47166HIGH A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware | May 1, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-24583HIGH Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbit | Jul 6, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-24582HIGH Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbit | Jul 6, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-23546HIGH A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack can lead to increased privilege | Jul 6, 2023 | 8.1 | 25 | NO | NO |
CVE-2023-22299HIGH An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command exec | Jul 6, 2023 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (66 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (66 CVEs).
Media Mentions
Signals from CVEs in this product scope (66 CVEs).
Top CNAs Publishing CVEs For Ur32l
Top CWEs
Versions
No cataloged versions.