CVE CVE-2020-11881
Severity HIGH · CVSS 3.1 7.5
Weakness CWE-129
Affected versions not yet announced
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2020-09-14

What is the CVE-2020-11881 vulnerability?

This is an array index validation error (CWE-129) in the RouterOS SMB server. A remote unauthenticated attacker can send modified configuration request packets to crash the SMB server. The defect is identified internally as SUP-12964.

Which RouterOS versions are vulnerable?

The affected versions are RouterOS 6.41.3 up to 6.46.5 and 7.x versions up to 7.0 Beta5. The specific fixed version has not yet been announced in the available data.

Is my router at risk?

A router is exposed if the SMB server is active and reachable from untrusted networks. Since the SMB server is a file sharing service rarely used in production on routers, the attack surface is drastically reduced by disabling this service.

Is the CVE-2020-11881 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog, nor is it flagged by ENISA as exploited. There is no evidence of active exploitation.

How to protect the router from CVE-2020-11881?

The primary measure is to disable the SMB server if it is not essential for network operations. Alternatively, you must update to a RouterOS version later than the vulnerable ones, ensuring that the installed release does not fall within the 6.41.3-6.46.5 or 7.x-7.0 Beta5 range.

Which RouterOS commands are needed to mitigate CVE-2020-11881?

Temporary mitigation: smb service

The defect concerns the router’s SMB file sharing server, which almost no one uses in production: it should be turned off.

/ip smb print
/ip smb set enabled=no

Update RouterOS

The only definitive fix is an update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2020-11881?

The CVSS v3.1 score assigned by NVD is 7.5, classified as HIGH severity. The vector indicates a network attack with low complexity, no privilege or user interaction requirements, and high impact on integrity.

Is authentication required to exploit CVE-2020-11881?

No, the vulnerability allows a remote unauthenticated attacker to crash the SMB server via modified packets.

What is the base weakness (CWE) of CVE-2020-11881?

The base weakness is CWE-129, defined as “Improper Validation of Array Index”.

Is the SMB server a common service on MikroTik routers?

No, the SMB server is a file sharing service that almost no one uses in production on routers. The operational recommendation is to keep it off to reduce the attack surface.

Official sources