| CVE | CVE-2020-22844 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 |
| Weakness | CWE-401 |
| Affected versions | not yet disclosed |
| Fixed version | not yet disclosed |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2022-02-28 |
What is the CVE-2020-22844 vulnerability?
CVE-2020-22844 is a buffer overflow present in Mikrotik RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service (DoS) by sending specially crafted SMB requests. The underlying weakness is classified as “Missing Release of Memory after Effective Lifetime” (CWE-401).
Which RouterOS versions are vulnerable?
The vulnerability description explicitly states that RouterOS version 6.47 is affected. The specific affected versions and fixed versions have not been disclosed in the available sources.
Is my router at risk?
A router is exposed to CVE-2020-22844 if it runs RouterOS 6.47, has the SMB file sharing service enabled, and is reachable from untrusted networks. Since the SMB service is rarely used in production environments, the risk is significantly reduced if this service is disabled.
Is the CVE-2020-22844 vulnerability actively exploited?
As of the date of this article, there is no evidence that CVE-2020-22844 is being actively exploited. The vulnerability is not listed in the CISA KEV catalog, and ENISA does not report it as being exploited.
How to protect the router from CVE-2020-22844?
The primary measure is to update the firmware to a version later than 6.47, if available and stable. Alternatively, you can mitigate the risk by completely disabling the SMB service on the router, as the vulnerability requires interaction with this specific component to be exploited.
Which RouterOS commands are needed to mitigate CVE-2020-22844?
Temporary mitigation: smb service
The flaw concerns the router’s SMB file sharing server, which almost no one uses in production: it should be turned off.
/ip smb print
/ip smb set enabled=no
Update RouterOS
The only definitive fix is an update. Save the configuration first; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
Does CVE-2020-22844 require authentication to be exploited?
No, CVE-2020-22844 allows an unauthenticated attacker to cause a denial of service through malicious SMB requests.
What is the CVSS score for CVE-2020-22844?
The CVSS v3.1 score assigned to CVE-2020-22844 is 7.5, with a severity classified as HIGH.
Is disabling the SMB service enough to protect against CVE-2020-22844?
Yes, disabling the SMB service eliminates the specific attack surface for CVE-2020-22844, as the vulnerability manifests exclusively through requests to the SMB server.
Is CVE-2020-22844 in the CISA KEV catalog?
No, CVE-2020-22844 is not included in the CISA KEV catalog and is not reported as actively exploited.



