{"id":"CVE-2023-43261","title":"An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.","summary":"An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-532","CWE-532"],"vendor":"milesight","product":"ur5x_firmware","affected":["ur5x_firmware < 35.3.0.7","ur32l_firmware < 35.3.0.7","ur32_firmware < 35.3.0.7","ur35_firmware < 35.3.0.7","ur41_firmware < 35.3.0.7"],"patched":["ur5x_firmware 35.3.0.7","ur32l_firmware 35.3.0.7","ur32_firmware 35.3.0.7","ur35_firmware 35.3.0.7","ur41_firmware 35.3.0.7"],"published":"2023-10-04","updated":"2026-07-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-43261","references":[{"url":"http://milesight.com","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/176988/Milesight-UR5X-UR32L-UR32-UR35-UR41-Credential-Leakage.html","label":"cve@mitre.org"},{"url":"https://github.com/win3zz/CVE-2023-43261","label":"cve@mitre.org"},{"url":"https://medium.com/@win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf","label":"cve@mitre.org"},{"url":"https://support.milesight-iot.com/support/home","label":"cve@mitre.org"},{"url":"http://milesight.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/176988/Milesight-UR5X-UR32L-UR32-UR35-UR41-Credential-Leakage.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://ur5x.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/win3zz/CVE-2023-43261","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://medium.com/%40win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.milesight-iot.com/support/home","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.59609,"epssPercentile":0.99085,"ingestedAt":"2026-07-04T17:56:38.241Z","exploits":{"github":1,"githubRepos":["https://github.com/win3zz/CVE-2023-43261"],"nuclei":["CVE-2023-43261"],"checkedAt":"2026-09-23T07:13:25.901Z"},"exploitAvailable":true,"slug":"CVE-2023-43261","body":"## Overview\n\nAn information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.\n\n## Affected\n\n- `ur5x_firmware < 35.3.0.7`\n- `ur32l_firmware < 35.3.0.7`\n- `ur32_firmware < 35.3.0.7`\n- `ur35_firmware < 35.3.0.7`\n- `ur41_firmware < 35.3.0.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ur5x_firmware 35.3.0.7`\n- `ur32l_firmware 35.3.0.7`\n- `ur32_firmware 35.3.0.7`\n- `ur35_firmware 35.3.0.7`\n- `ur41_firmware 35.3.0.7`","depth":"midnight","depthScore":65,"depthScoreParts":{"impact":41.3,"likelihood":11.9,"exploitation":12,"ransomware":0},"changes":[{"seq":4662,"id":"CVE-2023-43261","ts":1788887197593,"field":"exploit_available","old":"false","new":"true"},{"seq":3545,"id":"CVE-2023-43261","ts":1788886313704,"field":"exploit_available","old":"true","new":"false"},{"seq":2399,"id":"CVE-2023-43261","ts":1788882982988,"field":"exploit_available","old":"false","new":"true"},{"seq":1428,"id":"CVE-2023-43261","ts":1788882395910,"field":"exploit_available","old":"true","new":"false"},{"seq":542,"id":"CVE-2023-43261","ts":1788881832235,"field":"exploit_available","old":"false","new":"true"}]}