CVE-2023-43261 is an information disclosure vulnerability in Milesight industrial cellular routers, including at least UR5X, UR32L, UR32, UR35, and UR41 according to the CVE description, though supporting analysis indicates the public affected-version data may be inaccurate for some models. The issue allows a remote unauthenticated attacker to access sensitive files exposed by the web interface over HTTP, notably httpd.log and reportedly other log files such as system.log. These files can contain sensitive material including web administration credentials, VPN credentials, wireless keys, and DDNS credentials. In particular, httpd.log may record usernames and encrypted passwords used for successful web logins. Supporting research states the password material can be decrypted because the client-side JavaScript contains hardcoded AES keys and IVs, making recovery of usable administrator credentials feasible once the log is obtained. Successful exploitation therefore begins with unauthenticated retrieval of exposed log files and can lead to compromise of the router management interface.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2023-43261, a critical information disclosure vulnerability affecting Milesight Industrial Cellular Routers (UR5X, UR32L, UR32, UR35, UR41, and possibly others). The vulnerability arises from directory listing being enabled on the router, making sensitive log files (such as '/lang/log/httpd.log') publicly accessible via HTTP(S). These logs contain usernames and AES-encrypted passwords, which the script can extract and decrypt using a hardcoded key and IV. The main exploit script, 'CVE-2023-43261.py', takes a target URL (or a list of URLs) and attempts to retrieve and decrypt credentials from the exposed log file. The README provides detailed usage instructions, affected products, and references. The exploit is a PoC and does not provide post-exploitation capabilities beyond credential extraction. The attack vector is network-based, requiring HTTP(S) access to the vulnerable endpoint. No fake or malicious code is present; the exploit is legitimate and focused on demonstrating the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A misconfiguration in Milesight UR35 industrial cellular routers that made sensitive files, including encrypted administrator passwords and their decryption keys, publicly accessible via the web interface, allowing attackers to gain full administrative access.
An information disclosure / authentication bypass chain in Milesight industrial cellular routers where unauthenticated access to sensitive log files exposes encrypted admin credentials that can be decrypted using hardcoded AES material in client-side JavaScript, enabling remote unauthorized access.
An information disclosure issue in Milesight industrial cellular routers where unauthenticated attackers can retrieve httpd.log containing sensitive credentials (web/VPN/Wi‑Fi/DDNS), enabling credential recovery and subsequent administrative access/pivoting into connected ICS/industrial networks.
An information disclosure issue in Milesight industrial cellular routers where unauthenticated remote access to httpd.log can expose sensitive credentials (web/VPN/Wi‑Fi/DDNS). Because credentials are recoverable (static key/IV), this can enable subsequent authenticated access and potential pivoting into ICS/industrial-adjacent networks.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.