CVE-2023-25087 | Milesight UR32L 32.3.0.5 HTTP Request vtysh_ubus firewall_handler_set index/to_dport buffer overflow (TALOS-2023-1716)
A vulnerability identified as critical has been detected in Milesight UR32L 32.3.0.5. Affected by this issue is the function firewall_handler_set of the file vtysh_ubus of the component HTTP Request Handler. This manipulation of the argument index/to_dport causes buffer overflow.
The identification of this vulnerability is CVE-2023-25087. The attack needs to be done within the local network. Furthermore, there is an exploit available.