CVE CVE-2024-54952
Severity HIGH · CVSS 3.1 7.5
Weakness CWE-476
Affected versions not yet announced
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2025-05-29

What is the CVE-2024-54952 vulnerability?

CVE-2024-54952 is a memory corruption vulnerability in the SMB service that allows an unauthenticated remote attacker to send specially crafted packets to trigger a NULL Pointer Dereference. This behavior leads to a remote Denial of Service, making the SMB service unavailable.

Which RouterOS versions are vulnerable?

The description indicates that version 6.40.5 is affected by the vulnerability. Fixed versions have not yet been announced.

Is my router at risk?

A router is exposed if the SMB service is active and reachable from untrusted networks. Since the flaw specifically concerns the SMB file sharing server, devices that do not use this service or have disabled it are not directly vulnerable to this specific flaw.

Is the CVE-2024-54952 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of active exploitation.

How to protect the router from CVE-2024-54952?

The primary mitigation is to update RouterOS to a version that fixes the flaw, when available. Alternatively or additionally, it is advisable to disable the SMB service if it is not required for network operations, as the vulnerability requires direct interaction with this component.

Which RouterOS commands are needed to mitigate CVE-2024-54952?

Temporary mitigation: smb service

The flaw concerns the router’s SMB file sharing server, which almost no one uses in production: turn it off.

/ip smb print
/ip smb set enabled=no

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2024-54952?

The CVSS v3.1 score assigned to CVE-2024-54952 is 7.5, classified as HIGH severity.

Does CVE-2024-54952 require authentication to be exploited?

No, CVE-2024-54952 can be exploited by a remote attacker without the need for authentication.

What is the technical weakness underlying CVE-2024-54952?

The CVE-2024-54952 vulnerability is caused by a NULL Pointer Dereference (CWE-476) in the SMB service.

Official sources