CVE-2025-4043: Milesight UG65-868M-EA Improper Access Control for Volatile Memory Containing Boot Code
An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4043?
CVE-2025-4043 has a high severity rating due to the potential for unauthorized write access to critical system files.
How do I fix CVE-2025-4043?
To fix CVE-2025-4043, update the Milesight UG65-868M-EA firmware to version 60.0.0.46 or later.
What risks are associated with CVE-2025-4043?
CVE-2025-4043 allows an admin user to modify the /etc/rc.local file, which could lead to unauthorized code execution at system boot.
How can I verify if my device is affected by CVE-2025-4043?
Check if your Milesight UG65-868M-EA device is running a firmware version prior to 60.0.0.46 to determine if it is affected.
Is there a workaround for CVE-2025-4043 if I can't update my firmware?
A temporary workaround for CVE-2025-4043 could involve restricting access to admin accounts or monitoring changes to the /etc/rc.local file until the firmware can be updated.