CVE-2023-25110: Buffer Overflow
Multiple buffer overflow vulnerabilities exist in the vtyshubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the setgre function with the remotevirtualip variable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25110?
CVE-2023-25110 is a vulnerability that exists in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 firmware due to the use of an unsafe sprintf pattern.
What is the severity of CVE-2023-25110?
CVE-2023-25110 has a severity rating of 7.2 (high).
How can CVE-2023-25110 be exploited?
CVE-2023-25110 can be exploited by sending a specially crafted HTTP request that triggers a buffer overflow and allows arbitrary code execution.
Which software versions are affected by CVE-2023-25110?
Milesight UR32L v32.3.0.5 firmware is affected by CVE-2023-25110.
Is Milesight UR32L v32.3.0.5 firmware vulnerable to CVE-2023-25110?
Yes, Milesight UR32L v32.3.0.5 firmware is vulnerable to CVE-2023-25110.