VYPR
Unrated severityNVD Advisory· Published May 1, 2024· Updated Nov 4, 2025

CVE-2023-47166

CVE-2023-47166

Description

A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network request to trigger this vulnerability.

Affected products

2
  • Milesight/UR32Lllm-create2 versions
    = v32.3.0.7-r2+ 1 more
    • (no CPE)range: = v32.3.0.7-r2
    • (no CPE)range: v32.3.0.7-r2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.