CVE-2023-25104 | Milesight UR32L 32.3.0.5 HTTP Request vtysh_ubus set_ike_profile username/password stack-based overflow (TALOS-2023-1716)
A vulnerability, which was classified as critical, was found in Milesight UR32L 32.3.0.5. Affected by this vulnerability is the function set_ike_profile of the file vtysh_ubus of the component HTTP Request Handler. Executing manipulation of the argument username/password can lead to stack-based buffer overflow.
This vulnerability is registered as CVE-2023-25104. It is possible to launch the attack remotely. Furthermore, an exploit is available.