Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Milesight released the latest firmware Version 60.0.0.46 for the UG65 gateway. Users can download the latest firmware from the Milesight download center. https://www.milesight.com/iot/resources/download-center/#firmware-ug65 Please contact Milesight technical support https://www.milesight.com/company/contactus for more information about this issue and for instructions for installing the latest firmware.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13931 | An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 23 Jun 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Milesight
Milesight ug65-868m-ea Milesight ug65-868m-ea Firmware |
|
| CPEs | cpe:2.3:h:milesight:ug65-868m-ea:-:*:*:*:*:*:*:* cpe:2.3:o:milesight:ug65-868m-ea_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Milesight
Milesight ug65-868m-ea Milesight ug65-868m-ea Firmware |
Thu, 08 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot. | |
| Title | Milesight UG65-868M-EA Improper Access Control for Volatile Memory Containing Boot Code | |
| Weaknesses | CWE-1274 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-05-08T15:12:07.048Z
Reserved: 2025-04-28T16:04:15.727Z
Link: CVE-2025-4043
Updated: 2025-05-08T15:11:43.951Z
Status : Analyzed
Published: 2025-05-07T21:16:04.643
Modified: 2025-06-23T15:02:15.940
Link: CVE-2025-4043
No data.
OpenCVE Enrichment
No data.
EUVD