Multiple Buffer Overflow Vulnerabilities in Milesight UR32L Firewall
CVE-2023-25083
7.2HIGH
What is CVE-2023-25083?
Multiple buffer overflow vulnerabilities are present in the vtysh_ubus binary of the Milesight UR32L product, specifically in version 32.3.0.5. These vulnerabilities arise from using an unsafe sprintf pattern, which can be exploited via specially crafted HTTP requests by an attacker with elevated privileges. If successfully executed, this could allow the attacker to run arbitrary code on the system. The vulnerability is triggered within the firewall_handler_set function, affecting both the ip and mac variables, thereby compromising the firewall's integrity.
Affected Version(s)
UR32L v32.3.0.5
