Ur32l

Vendor:

First CVE: Jul 6, 2023 · Active for 3 years

66
Total CVEs
More Total CVEs than 98% of tracked products
33.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ur32l over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 6, 2023
3 years ago
Most Recent CVE
May 1, 2024
817 days ago

CVE Severity & Scoring

Ur32l66 CVEs
All CVEs352,727 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network66 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low64 (97.0%)
High2 (3.0%)
Unknown0 (0.0%)
User Interaction
None63 (95.5%)
Unknown0 (0.0%)
Required3 (4.5%)
Privileges Required
Low7 (10.6%)
High51 (77.3%)
None8 (12.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (66 CVEs).

66 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
Oct 4, 20237.572NOYES
A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An att
Jul 6, 20239.831NONO
An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command exe
Jul 6, 20238.828NONO
Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to
Jul 6, 20238.826NONO
Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to
Jul 6, 20238.826NONO
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware
May 1, 20248.825NONO
Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbit
Jul 6, 20238.825NONO
Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbit
Jul 6, 20238.825NONO
A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack can lead to increased privilege
Jul 6, 20238.125NONO
An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command exec
Jul 6, 20238.825NONO

Exploit Exposure

Signals from CVEs in this product scope (66 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (66 CVEs).

Media Mentions

Signals from CVEs in this product scope (66 CVEs).

Top CNAs Publishing CVEs For Ur32l

Top CWEs

Versions

No cataloged versions.