CVE-2023-25582: OS Command Injection
Two OS command injection vulnerabilities exist in the zebra vlanname functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages an already existing vlan configuration.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the OS command injection in Milesight UR32L v32.3.0.5?
The vulnerability ID for the OS command injection in Milesight UR32L v32.3.0.5 is CVE-2023-25582.
What is the severity rating of CVE-2023-25582?
CVE-2023-25582 has a severity rating of 7.2, which is considered high.
What is affected by CVE-2023-25582?
CVE-2023-25582 affects Milesight UR32L v32.3.0.5 firmware.
How can an attacker exploit CVE-2023-25582?
An attacker can exploit CVE-2023-25582 by sending a specially crafted network request to trigger the OS command injection vulnerabilities in Milesight UR32L v32.3.0.5.
Is Milesight UR32L v32.3.0.5 vulnerable to CVE-2023-25582?
Yes, Milesight UR32L v32.3.0.5 is vulnerable to CVE-2023-25582.