| CVE | CVE-2018-5951 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 |
| Weakness | not yet disclosed |
| Affected versions | not yet disclosed |
| Fixed version | not yet disclosed |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2020-03-02 |
What is the CVE-2018-5951 vulnerability?
The vulnerability consists of an attacker’s ability to send a 1-byte packet to an IPv6 address on the router, specifying IP protocol 97. This event causes an immediate reboot of the RouterOS operating system. The original description specifies that all versions of RouterOS supporting the EoIPv6 (Ethernet over IPv6) feature are affected.
Which RouterOS versions are vulnerable?
Specific information about affected versions and the fixed version has not yet been disclosed in the reference database. The vulnerability description generally indicates that all versions of RouterOS supporting EoIPv6 are vulnerable, but no specific version numbers or a stable fixed release are listed.
Is my router at risk?
A router is exposed to CVE-2018-5951 if it runs a version of RouterOS with EoIPv6 support and if the device’s IPv6 address is reachable from untrusted networks. Since the attack requires sending a specific packet to the IPv6 address, the attack surface depends on the configuration of active IPv6 services and the exposure of the interface to the internet or external networks.
Is the CVE-2018-5951 vulnerability actively exploited?
As of the date of this article, there is no evidence that the vulnerability is being actively exploited. CISA does not include it in the KEV catalog, and ENISA does not report it as the subject of known exploits.
How to protect the router from CVE-2018-5951?
The primary mitigation is to ensure that the router’s IPv6 address is not reachable from untrusted networks, for example by filtering incoming traffic towards the interface exposed to the internet. If the EoIPv6 feature is not required for your network operations, it is advisable to disable it or remove the configuration associated with IP protocol 97. Updating to a version of RouterOS that removes or fixes this specific packet handling is the definitive solution, but since the specific fixed version has not yet been disclosed, IPv6 traffic filtering measures represent the immediate protection.
Which RouterOS commands are needed to mitigate CVE-2018-5951?
Update RouterOS
The only definitive fix is an update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2018-5951?
The CVSS v3.1 score assigned to CVE-2018-5951 is 7.5, with a severity classified as HIGH. The vector indicates that the attack is remote, requires low complexity, does not require user privileges or user interaction, and has a high impact on system availability.
Does CVE-2018-5951 require authentication to be exploited?
No, CVE-2018-5951 does not require authentication. The CVSS vector indicates “PR:N” (Privileges Required: None), which means an attacker can exploit the vulnerability without holding valid credentials on the router.
Does disabling EoIPv6 protect against CVE-2018-5951?
Yes, disabling the EoIPv6 feature or preventing the reception of packets with IP protocol 97 towards the router’s IPv6 address mitigates the risk. Since the vulnerability is specifically linked to EoIPv6 support, removing this capability or filtering the associated traffic eliminates the described attack vector.
Is CVE-2018-5951 listed in CISA’s KEV catalog?
No, CVE-2018-5951 is not listed in CISA’s KEV (Known Exploited Vulnerabilities) catalog. The “known_exploited” field is indicated as false, and there is no record of it being added to the catalog.



