Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2023-25092 Details

Description

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the handle_interface_acl function with the interface and out_acl variables.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-787Out-of-bounds Write[email protected]
CWE-121Stack-based Buffer Overflow[email protected]

Affected Products

ProductVersions
milesight ur32l firmware
32.3.0.5

CPE

  • cpe:2.3:o:milesight:ur32l_firmware:32.3.0.5:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
milesight ur32l
All versions

CPE

  • cpe:2.3:h:milesight:ur32l:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

10 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2023-25092
NVD Published Date:
Jul 6, 2023
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2023-25092 Details - Not Deferred