Vulnerability record · CVE-2023-43261 · published 4 October 2023
CVE-2023-43261: Milesight industrial routers leak sensitive data via log files
Milesight · Ur5x Firmware
Milesight UR5X, UR32L, UR32, UR35 and UR41 routers before firmware v35.3.0.7 expose sensitive information, mapped to CWE-532 (sensitive information in log files). A public exploit and write-up exist, so the flaw is well understood and easy to reproduce.
Description
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable information disclosure with a public exploit and very high EPSS, though no KEV listing or confirmed in-the-wild campaign.
What it is
Milesight UR5X, UR32L, UR32, UR35 and UR41 routers before firmware v35.3.0.7 expose sensitive information, mapped to CWE-532 (sensitive information in log files). A public exploit and write-up exist, so the flaw is well understood and easy to reproduce.
Impact
An unauthenticated remote attacker can read sensitive router components, including credential material per the public exploit title, enabling further access to the device or connected industrial networks.
Attack surface
Reachable over the network with no authentication and no user interaction (CVSS vector AV:N/AC:L/PR:N/UI:N). The exact exposed endpoint is not detailed in the record, but the flaw is network-facing on the router itself.
Exploitation
Not listed in CISA KEV, but EPSS is 0.596 (99th percentile) and references include a public exploit repository and a Packet Storm credential-leakage advisory, indicating active public exploitation tooling.
What to do
- Upgrade affected routers to firmware v35.3.0.7 or later; this is the only fix stated in the record.
- Restrict management and web interfaces to trusted networks or VPN; do not expose routers directly to the internet.
- Rotate any credentials, keys or secrets that may have been written to logs or exposed by the device.
- Monitor vendor support pages for further firmware guidance and interim workarounds.
Detection
- Inspect router log files and exposed endpoints for credential or configuration data leakage.
- Monitor network traffic to router management interfaces for anomalous or unexpected requests.
- Alert on access to known exploit paths from the public proof-of-concept repository.
- Review authentication logs for logins using credentials that may have leaked from device logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-43261 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-43261), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.