CVE-2023-25087: CWE-121: Stack-based Buffer Overflow in Milesight UR32L
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the firewall_handler_set function with the index and to_dport variables.
CVE-2023-25087: CWE-121: Stack-based Buffer Overflow in Milesight UR32L
Description
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the firewall_handler_set function with the index and to_dport variables.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- talos
- Date Reserved
- 2023-02-02T20:42:36.069Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 690a53152a90255b94da57ab
Added to database: 11/4/2025, 7:25:09 PM
Last updated: 11/4/2025, 7:26:56 PM
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
CVE-2023-40395: An app may be able to access contacts in Apple iOS and iPadOS
UnknownCVE-2023-40391: An app may be able to disclose kernel memory in Apple iOS and iPadOS
UnknownCVE-2023-40390: An app may be able to access user-sensitive data in Apple macOS
MediumCVE-2023-40388: Safari may save photos to an unprotected location in Apple macOS
UnknownCVE-2023-40386: An app may be able to access Notes attachments in Apple macOS
UnknownActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.