CVE-2023-43261: Milesight UR32 Firmware

High severity, CVSS 7.5. EPSS: 63.7% chance of exploitation in the next 30 days.

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

Affected products

  • Milesight UR32 Firmware: before 35.3.0.7 (fixed in 35.3.0.7)
  • Milesight UR32L Firmware: before 35.3.0.7 (fixed in 35.3.0.7)
  • Milesight UR35 Firmware: before 35.3.0.7 (fixed in 35.3.0.7)
  • Milesight UR41 Firmware: before 35.3.0.7 (fixed in 35.3.0.7)
  • Milesight UR5X Firmware: before 35.3.0.7 (fixed in 35.3.0.7)

Published 2023-10-04. Last modified 2026-07-09.