CVE-2023-25096 | Milesight UR32L 32.3.0.5 HTTP Request vtysh_ubus set_qos rule_name stack-based overflow (TALOS-2023-1716)
A vulnerability was found in Milesight UR32L 32.3.0.5 and classified as critical. Affected is the function set_qos of the file vtysh_ubus of the component HTTP Request Handler. Executing manipulation of the argument rule_name can lead to stack-based buffer overflow.
This vulnerability appears as CVE-2023-25096. The attack may be performed from remote. In addition, an exploit is available.