CVE-2023-25114 | Milesight UR32L 32.3.0.5 HTTP Request vtysh_ubus set_openvpn_client expert_options stack-based overflow (TALOS-2023-1716)
A vulnerability classified as critical has been found in Milesight UR32L 32.3.0.5. This affects the function set_openvpn_client of the file vtysh_ubus of the component HTTP Request Handler. This manipulation of the argument expert_options causes stack-based buffer overflow.
This vulnerability is tracked as CVE-2023-25114. The attack is possible to be carried out remotely. Moreover, an exploit is present.