OS Command Injection Vulnerability in Milesight UR32L by Milesight
CVE-2023-23550
7.2HIGH
What is CVE-2023-23550?
An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of the Milesight UR32L v32.3.0.5. This flaw allows an attacker to craft a specialized network packet that can lead to unauthorized command execution on the device. By sending a sequence of targeted requests, an attacker could exploit this vulnerability, potentially compromising the integrity and security of the affected system.
Affected Version(s)
UR32L v32.3.0.5
