| CVE | CVE-2019-13955 |
|---|---|
| Severity | not yet disclosed |
| Weakness | CWE-674 |
| Affected versions | < 6.44.5 |
| First non-vulnerable version | 6.44.5 (per branch) |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2019-07-26 |
What is the CVE-2019-13955 vulnerability?
CVE-2019-13955 is a stack exhaustion vulnerability that allows a remote authenticated attacker to crash the HTTP server by sending a specially crafted HTTP request. The crash occurs due to uncontrolled recursion during JSON parsing. It is not possible to inject malicious code.
Which RouterOS versions are vulnerable?
RouterOS versions prior to 6.44.5 of the long-term release branch are vulnerable. The specific corrective version is not indicated in the available data, but upgrading to a version later than 6.44.5 resolves the issue.
Is my router at risk?
A router is at risk if the WebFig service (web management interface) is active and reachable from untrusted networks. If the WebFig service is not used, it should be disabled. If it is used, it must be accessible exclusively from the internal administration network.
Is the CVE-2019-13955 vulnerability actively exploited?
As of the date of the article, there is no evidence that the vulnerability is being actively exploited. It is not present in the CISA KEV catalog and there are no reports from ENISA.
How to protect the router from CVE-2019-13955?
Update RouterOS to a version later than 6.44.5 of the long-term release branch. Alternatively, disable the WebFig service if not necessary. If the service must remain active, restrict its access to the internal administration network only and ensure that authenticated users are trusted.
Which RouterOS commands are needed to mitigate CVE-2019-13955?
Temporary mitigation: www service
The defect concerns the web management service (WebFig). If you do not use it, turn it off; if you do use it, it must be reachable only from the administration network.
# quali servizi di gestione sono attivi e da dove sono raggiungibili
/ip service print
# se WebFig non serve: spegnilo
/ip service set www disabled=yes
/ip service set www-ssl disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set www address=192.168.88.0/24
/ip service set www-ssl address=192.168.88.0/24
Update RouterOS
The only definitive fix is the update. First, save the configuration; the installation restarts the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
Does CVE-2019-13955 require authentication to be exploited?
Yes, CVE-2019-13955 requires the attacker to be authenticated on the router to exploit the vulnerability and crash the HTTP server.
Which RouterOS version fixes CVE-2019-13955?
Version 6.44.5 of the long-term release branch fixes CVE-2019-13955. Versions prior to this are vulnerable.
Is disabling WebFig enough to protect against CVE-2019-13955?
Yes, disabling the WebFig service eliminates the attack surface for CVE-2019-13955, as the vulnerability specifically concerns the HTTP server managed by this service.
Is CVE-2019-13955 present in the CISA KEV catalog?
No, CVE-2019-13955 is not present in the CISA KEV catalog and is not reported as being actively exploited as of the date of the article.



