CVE CVE-2017-20149
Severity CRITICAL · CVSS 3.1 9.8
Weakness CWE-787
Affected versions < 6.37.5, < 6.38.5
First non-vulnerable version 6.37.5, 6.38.5 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2022-10-15

What is the CVE-2017-20149 vulnerability?

CVE-2017-20149 is an “Out-of-bounds Write” weakness (CWE-787) in the RouterOS web server. An unauthenticated remote user can send a specific HTTP request to cause memory corruption, allowing arbitrary code execution on the system.

Which RouterOS versions are vulnerable?

The vulnerable versions are those lower than 6.37.5 and lower than 6.38.5. The exact corrective version is not specified in the available data, but updating to a release later than these thresholds eliminates the vulnerability.

Is my router at risk?

A router is at risk if it runs a RouterOS version earlier than 6.37.5 or 6.38.5 and its web server is reachable from untrusted networks. Since the attack only requires sending an HTTP request without authentication, the risk exposure depends on the reachability of the web service by external actors.

Is the CVE-2017-20149 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog nor reported as exploited by ENISA, so it is not considered actively exploited according to the cited official sources.

How to protect the router from CVE-2017-20149?

The only effective mitigation is to update RouterOS to a version later than 6.37.5 or 6.38.5. No specific alternative mitigations are available, so updating the firmware is mandatory to eliminate the risk of arbitrary code execution.

Which RouterOS commands are needed to mitigate CVE-2017-20149?

Update RouterOS

The only definitive fix is the update. First, save the configuration; the installation restarts the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score of CVE-2017-20149?

The CVSS v3.1 score of CVE-2017-20149 is 9.8, classified as CRITICAL, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Is authentication required to exploit CVE-2017-20149?

No, CVE-2017-20149 can be exploited by an unauthenticated remote user sending a specific HTTP request to the RouterOS web server.

Which RouterOS versions fix CVE-2017-20149?

CVE-2017-20149 is present in versions lower than 6.37.5 and lower than 6.38.5; updating to versions later than these eliminates the vulnerability.

Is CVE-2017-20149 in the CISA KEV catalog?

No, CVE-2017-20149 is not included in the CISA KEV catalog as of the date of the article.

Official sources