CVE CVE-2020-22845
Severity HIGH · CVSS 3.1 7.5
Weakness CWE-120
Affected versions not yet disclosed
Fixed version not yet disclosed
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2022-02-28

What is the CVE-2020-22845 vulnerability?

CVE-2020-22845 is a buffer overflow in the FTP service of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service (DoS) by sending specially crafted FTP requests. The flaw falls under the CWE-120 category, defined as “Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’)”.

Which RouterOS versions are vulnerable?

The version specifically identified as vulnerable is RouterOS 6.47. The affected versions and the exact fixed version have not been disclosed in available sources.

Is my router at risk?

A router is at risk if it is running RouterOS 6.47, has the FTP service enabled, and is reachable from untrusted networks. Since the flaw concerns a cleartext service that should not be enabled on any modern router, the exposure depends on the specific device configuration.

Is the CVE-2020-22845 vulnerability actively exploited?

As of the date of the article, CVE-2020-22845 is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of active exploitation.

How to protect the router from CVE-2020-22845?

The primary mitigation is to update RouterOS to a version later than 6.47 that does not contain this flaw. Alternatively, you can completely disable the FTP service if it is not required for network operations, thereby eliminating the attack surface.

Which RouterOS commands are needed to mitigate CVE-2020-22845?

Temporary mitigation: legacy service

The flaw concerns cleartext services (Telnet, FTP) that should not be enabled on any modern router.

/ip service set telnet disabled=yes
/ip service set ftp disabled=yes

Update RouterOS

The only definitive fix is an update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2020-22845?

CVE-2020-22845 has a CVSS v3.1 score of 7.5, classified as HIGH severity, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.

Does CVE-2020-22845 require authentication to be exploited?

No, CVE-2020-22845 allows an unauthenticated attacker to cause a denial of service through malicious FTP requests.

What is the CWE category associated with CVE-2020-22845?

CVE-2020-22845 is associated with the CWE-120 category, defined as “Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’)”.

Is the FTP service the only service involved in CVE-2020-22845?

Yes, the vulnerability description specifies that the buffer overflow occurs in the FTP service of RouterOS 6.47.

Official sources