We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-4043

Milesight UG65-868M-EA Improper Access Control for Volatile Memory Containing Boot Code



Description

An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot.

Reserved 2025-04-28 | Published 2025-05-07 | Updated 2025-05-08 | Assigner icscert


MEDIUM: 6.8CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

MEDIUM: 6.1CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N

Problem types

CWE-1274

Product status

Default status
unaffected

Any version before 60.0.0.46
affected

Credits

Joe Lovett of Pen Test Partners reported this vulnerability to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-25-126-02

www.milesight.com/iot/resources/download-center/

cve.org (CVE-2025-4043)

nvd.nist.gov (CVE-2025-4043)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-4043

Support options

Helpdesk Chat, Email, Knowledgebase