Information Disclosure in Milesight Routers Affects Multiple Models
CVE-2023-43261
Key Information:
- Vendor
Milesight
- Status
- Vendor
- CVE Published:
- 4 October 2023
Badges
What is CVE-2023-43261?
An information disclosure vulnerability in Milesight's range of routers, including models UR5X, UR32L, UR32, UR35, and UR41, prior to version 35.3.0.7, allows unauthorized access to sensitive router components. This exposure can potentially enable attackers to obtain confidential information, raising significant security concerns for users and organizations that rely on these devices for their network infrastructure.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
93% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability Reserved
