CVE-2023-25097 | Milesight UR32L 32.3.0.5 HTTP Request vtysh_ubus set_qos attach_class buffer overflow (TALOS-2023-1716)
A vulnerability was found in Milesight UR32L 32.3.0.5. It has been classified as critical. Affected by this vulnerability is the function set_qos of the file vtysh_ubus of the component HTTP Request Handler. The manipulation of the argument attach_class leads to buffer overflow.
This vulnerability is traded as CVE-2023-25097. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.