MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability
MikroTik — RouterOS
- Added to KEV catalog
- 8 September 2022
- Federal remediation due date
- 29 September 2022
- Weakness classification (CWE)
- CWE-119
CISA Description
In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.
Required action
Apply updates per vendor instructions.
Notes
https://www.coresecurity.com/core-labs/advisories/mikrotik-routeros-smb-buffer-overflow#vendor_update, https://mikrotik.com/download; https://nvd.nist.gov/vuln/detail/CVE-2018-7445
More MikroTik Vulnerabilities
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik Router OS Directory Traversal Vulnerability
Is this vulnerability present in your environment?
CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.
Explore VAPT Services







