Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the trace tool utility.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-28538 Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the trace tool utility.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Nov 2025 20:30:00 +0000


Thu, 14 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2025-11-04T19:14:45.135Z

Reserved: 2023-01-25T15:05:01.030Z

Link: CVE-2023-24520

cve-icon Vulnrichment

Updated: 2025-11-04T19:14:45.135Z

cve-icon NVD

Status : Modified

Published: 2023-07-06T15:15:12.180

Modified: 2025-11-04T20:16:18.637

Link: CVE-2023-24520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.