CVE-2023-25114: Buffer Overflow
Multiple buffer overflow vulnerabilities exist in the vtyshubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the setopenvpnclient function with the expertoptions variable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25114?
CVE-2023-25114 is a vulnerability in the vtysh_ubus binary of Milesight UR32L v32.3.0.5, which allows arbitrary code execution.
How severe is the CVE-2023-25114 vulnerability?
The severity of CVE-2023-25114 is high, with a CVSS score of 7.2.
What software versions are affected by CVE-2023-25114?
CVE-2023-25114 affects Milesight UR32L v32.3.0.5 firmware.
How can CVE-2023-25114 be exploited?
CVE-2023-25114 can be exploited by sending a specially crafted HTTP request.
Is there a fix available for CVE-2023-25114?
There is currently no information on an available fix for CVE-2023-25114.