July 6, 2023, 3:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages an already existing vlan configuration.

a network code command command injection configuration cve injection network request send trigger vlan vulnerabilities

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Penetration Tester, Retail Engineering, Early Career

@ Apple | Austin, Texas, United States

Principal Product Security Engineer

@ Palo Alto Networks | Bengaluru, India

Senior Manager/ Director, Cyber

@ McGrathNicol | Brisbane