| CVE | CVE-2019-16160 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 |
| Weakness | CWE-191 |
| Affected versions | < 6.45.5 |
| First non-vulnerable version | 6.45.5 (per branch) |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2020-10-07 |
What is the CVE-2019-16160 vulnerability?
CVE-2019-16160 is an integer underflow in the MikroTik RouterOS SMB server that allows a remote unauthenticated attacker to crash the service. The flaw is classified as CWE-191 (Integer Underflow (Wrap or Wraparound)).
Which RouterOS versions are vulnerable?
RouterOS versions prior to 6.45.5 are vulnerable. The exact corrective version is not specified in the available data, but upgrading to a version later than 6.45.5 resolves the issue.
Is my router at risk?
A router is at risk if it runs a RouterOS version prior to 6.45.5 and has the SMB service active and reachable from untrusted networks. If the SMB service is disabled or the router is not exposed to external networks, the risk is reduced.
Is the CVE-2019-16160 vulnerability actively exploited?
As of the date of the article, CVE-2019-16160 is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of active exploitation.
How to protect the router from CVE-2019-16160?
Update RouterOS to a version later than 6.45.5 to eliminate the vulnerability. Alternatively, disable the SMB service if it is not required in production, as the flaw specifically affects that component.
Which RouterOS commands are needed to mitigate CVE-2019-16160?
Temporary mitigation: smb service
The flaw affects the router’s SMB file sharing server, which almost no one uses in production: it should be turned off.
/ip smb print
/ip smb set enabled=no
Update RouterOS
The only definitive fix is an update. Save the configuration first; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2019-16160?
CVE-2019-16160 has a CVSS v3.1 score of 7.5, classified as HIGH. The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.
Is authentication required to exploit CVE-2019-16160?
No, CVE-2019-16160 can be exploited by a remote unauthenticated attacker. No credentials are required to cause the SMB service crash.
Is disabling the SMB service enough to mitigate CVE-2019-16160?
Yes, disabling the SMB service eliminates exposure to CVE-2019-16160, as the vulnerability resides exclusively in that component. However, updating to the fixed version remains the definitive solution.
Is CVE-2019-16160 in the CISA KEV catalog?
No, CVE-2019-16160 is not present in the CISA KEV catalog. It is not considered an actively exploited vulnerability according to CISA criteria.



