| CVE | CVE-2019-3943 |
|---|---|
| Severity | HIGH · CVSS 3.1 8.1 |
| Weakness | CWE-22, CWE-23 |
| Affected versions | Long-term 6.42.12 and below, Stable 6.43.12 and below, Testing 6.44beta75 and below |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2019-04-10 |
What is the CVE-2019-3943 vulnerability?
CVE-2019-3943 is an authenticated, remote directory traversal vulnerability affecting the HTTP or Winbox interfaces of RouterOS. An authenticated attacker can exploit this flaw to read and write files outside the sandbox directory /rw/disk. The underlying weaknesses are classified as “Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)” (CWE-22) and “Relative Path Traversal” (CWE-23).
Which RouterOS versions are vulnerable?
The vulnerable versions are: Long-term 6.42.12 and earlier, Stable 6.43.12 and earlier, and Testing 6.44beta75 and earlier. The fixed version has not yet been announced.
Is my router at risk?
A router is exposed if the HTTP or Winbox interfaces are active and reachable from untrusted networks. Specifically, access to Winbox (both via IP and via MAC address) must be restricted to the management network to reduce the risk. If the interface is accessible only from trusted internal networks and authentication is strict, the risk is contained, but exposure to the Internet or external networks significantly increases the likelihood of exploitation.
Is the CVE-2019-3943 vulnerability actively exploited?
As of the date of this article, CVE-2019-3943 is not listed in the CISA KEV catalog nor reported as exploited by ENISA.
How to protect the router from CVE-2019-3943?
The primary action is to update RouterOS to a version later than the vulnerable ones (Stable > 6.43.12, Long-term > 6.42.12, Testing > 6.44beta75). Alternatively or additionally, you can mitigate the risk by restricting access to the HTTP and Winbox interfaces exclusively to the trusted management network, disabling access from untrusted networks, and ensuring that only authorized users can authenticate.
Which RouterOS commands are needed to mitigate CVE-2019-3943?
Temporary mitigation: winbox service
The flaw affects Winbox, both via IP and via MAC address. Both access methods must be restricted to the management network.
/ip service print
# Winbox via IP solo dalla rete di gestione (sostituisci con la tua)
/ip service set winbox address=192.168.88.0/24
# Winbox via MAC: spegnilo, o limitalo a un'interface-list di gestione
/tool mac-server mac-winbox set allowed-interface-list=none
Update RouterOS
The only definitive fix is the update. Save the configuration first; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2019-3943?
The CVSS v3.1 score for CVE-2019-3943 is 8.1 (HIGH), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N, assigned by NVD.
Is authentication required to exploit CVE-2019-3943?
Yes, CVE-2019-3943 requires authentication: it is an authenticated remote vulnerability that exploits the HTTP or Winbox interfaces.
What is the EUVD ID for CVE-2019-3943?
The EUVD ID associated with CVE-2019-3943 is EUVD-2019-13550.
Which interfaces are affected by CVE-2019-3943?
The interfaces affected by CVE-2019-3943 are HTTP and Winbox, both via IP and via MAC address.
Is the Testing 6.44beta75 version the only vulnerable development version?
Yes, among the listed versions, only Testing 6.44beta75 is a development version; the indicated Stable and Long-term versions are stable releases.



