← Back to browse · API

CVE-2023-23902

Severity
CRITICAL
CVSS
9.8
EPSS
0.02212
Risk score
39.97
CISA KEV
No
PoC
No
Published
2023-07-06
Modified
2024-11-14
First seen
2026-08-07
Aliases
EUVD-2023-27985, GHSA-QPC6-5F38-PMPQ
Products
Milesight:UR32L v32.3.0.5
Sources
euvd EUVD-2023-27985

Description

A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An attacker can send a network request to trigger this vulnerability.

References