CVE-2023-25107 | Milesight UR32L 32.3.0.5 HTTP Request vtysh_ubus set_gre remote_mask stack-based overflow (TALOS-2023-1716)
A vulnerability has been found in Milesight UR32L 32.3.0.5 and classified as critical. Affected by this vulnerability is the function set_gre of the file vtysh_ubus of the component HTTP Request Handler. Performing manipulation of the argument remote_mask results in stack-based buffer overflow.
This vulnerability is known as CVE-2023-25107. Remote exploitation of the attack is possible. Furthermore, an exploit is available.