CVE-2023-25112 | Milesight UR32L 32.3.0.5 HTTP Request vtysh_ubus set_l2tp remote_mask stack-based overflow (TALOS-2023-1716)
A vulnerability was found in Milesight UR32L 32.3.0.5. It has been declared as critical. This vulnerability affects the function set_l2tp of the file vtysh_ubus of the component HTTP Request Handler. The manipulation of the argument remote_mask results in stack-based buffer overflow.
This vulnerability was named CVE-2023-25112. The attack may be performed from remote. In addition, an exploit is available.