CVE CVE-2019-3976
Severity HIGH · CVSS 3.1 8.8
Weakness CWE-22, CWE-23
Affected versions RouterOS 6.45.6 Stable and below. RouterOS 6.44.5 Long-term and below.
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2019-10-29

What is the CVE-2019-3976 vulnerability?

The vulnerability allows the creation of an arbitrary directory via the package name field in the update package. If an authenticated user installs a malicious package, they can create a directory and enable the developer shell.

Which RouterOS versions are vulnerable?

RouterOS 6.45.6 Stable and earlier versions, and RouterOS 6.44.5 Long-term and earlier versions, are vulnerable. The fixed version has not yet been announced.

Is my router at risk?

A router is exposed if it is running one of the indicated vulnerable versions and if a user with access credentials can install packages. Since the involved services are not specified, the risk depends on the attacker’s ability to authenticate and manage system updates.

Is the CVE-2019-3976 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog nor reported as exploited by ENISA.

How to protect the router from CVE-2019-3976?

Update RouterOS to a version later than 6.45.6 Stable and 6.44.5 Long-term. While waiting for the update, restrict administrative access to trusted networks only and monitor for the installation of unauthorized packages.

Which RouterOS commands are needed to mitigate CVE-2019-3976?

Update RouterOS

The only definitive fix is the update. First, save the configuration; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2019-3976?

The CVSS v3.1 score for CVE-2019-3976 is 8.8, with HIGH severity.

Does CVE-2019-3976 require authentication to be exploited?

Yes, CVE-2019-3976 requires the attacker to be an authenticated user on the router.

Which weaknesses (CWE) are associated with CVE-2019-3976?

The weaknesses associated with CVE-2019-3976 are CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)) and CWE-23 (Relative Path Traversal).

Is CVE-2019-3976 present in the CISA KEV catalog?

No, CVE-2019-3976 is not present in the CISA KEV catalog.

Official sources