CVE-2023-25100 | Milesight UR32L 32.3.0.5 HTTP Request vtysh_ubus set_qos default_class stack-based overflow (TALOS-2023-1716)
A vulnerability described as critical has been identified in Milesight UR32L 32.3.0.5. The impacted element is the function set_qos of the file vtysh_ubus of the component HTTP Request Handler. The manipulation of the argument default_class results in stack-based buffer overflow.
This vulnerability is identified as CVE-2023-25100. The attack can be executed remotely. Additionally, an exploit exists.