CVE-2023-25119 | Milesight UR32L 32.3.0.5 HTTP Request vtysh_ubus set_pptp remote_subnet/remote_mask stack-based overflow (TALOS-2023-1716)
A vulnerability categorized as critical has been discovered in Milesight UR32L 32.3.0.5. Impacted is the function set_pptp of the file vtysh_ubus of the component HTTP Request Handler. Such manipulation of the argument remote_subnet/remote_mask leads to stack-based buffer overflow.
This vulnerability is referenced as CVE-2023-25119. It is possible to launch the attack remotely. Furthermore, an exploit is available.