OS Command Injection in Milesight UR32L by Milesight
CVE-2023-22306
7.2HIGH
What is CVE-2023-22306?
An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5, which allows attackers to execute arbitrary commands. Specifically, a specially crafted network packet can trigger this flaw, enabling an attacker to send a sequence of requests that exploit the vulnerability for unauthorized command execution.
Affected Version(s)
UR32L v32.3.0.5
