---
id: CVE-2023-43261
title: >-
  An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before
  v35.3.0.7 allows attackers to access sensitive router components.
summary: >-
  An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before
  v35.3.0.7 allows attackers to access sensitive router components.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-532
  - CWE-532
vendor: milesight
product: ur5x_firmware
affected:
  - ur5x_firmware < 35.3.0.7
  - ur32l_firmware < 35.3.0.7
  - ur32_firmware < 35.3.0.7
  - ur35_firmware < 35.3.0.7
  - ur41_firmware < 35.3.0.7
patched:
  - ur5x_firmware 35.3.0.7
  - ur32l_firmware 35.3.0.7
  - ur32_firmware 35.3.0.7
  - ur35_firmware 35.3.0.7
  - ur41_firmware 35.3.0.7
published: '2023-10-04'
updated: '2026-07-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-43261'
references:
  - url: 'http://milesight.com'
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/176988/Milesight-UR5X-UR32L-UR32-UR35-UR41-Credential-Leakage.html
    label: cve@mitre.org
  - url: 'https://github.com/win3zz/CVE-2023-43261'
    label: cve@mitre.org
  - url: >-
      https://medium.com/@win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf
    label: cve@mitre.org
  - url: 'https://support.milesight-iot.com/support/home'
    label: cve@mitre.org
  - url: 'http://milesight.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/176988/Milesight-UR5X-UR32L-UR32-UR35-UR41-Credential-Leakage.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://ur5x.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/win3zz/CVE-2023-43261'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://medium.com/%40win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.milesight-iot.com/support/home'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.59609
epssPercentile: 0.99096
ingestedAt: '2026-07-04T17:56:38.241Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/win3zz/CVE-2023-43261'
  nuclei:
    - CVE-2023-43261
  checkedAt: '2026-09-26T09:05:29.992Z'
exploitAvailable: true
---

## Overview

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

## Affected

- `ur5x_firmware < 35.3.0.7`
- `ur32l_firmware < 35.3.0.7`
- `ur32_firmware < 35.3.0.7`
- `ur35_firmware < 35.3.0.7`
- `ur41_firmware < 35.3.0.7`

## Remediation

Upgrade past the affected range:

- `ur5x_firmware 35.3.0.7`
- `ur32l_firmware 35.3.0.7`
- `ur32_firmware 35.3.0.7`
- `ur35_firmware 35.3.0.7`
- `ur41_firmware 35.3.0.7`
