CVE-2023-25121 | Milesight UR32L 32.3.0.5 HTTP Request vtysh_ubus set_ike_profile secrets_local stack-based overflow (TALOS-2023-1716)
A vulnerability categorized as critical has been discovered in Milesight UR32L 32.3.0.5. The affected element is the function set_ike_profile of the file vtysh_ubus of the component HTTP Request Handler. Executing manipulation of the argument secrets_local can lead to stack-based buffer overflow.
This vulnerability is handled as CVE-2023-25121. The attack can be executed remotely. Additionally, an exploit exists.