| CVE | CVE-2019-3924 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 |
| Weakness | CWE-441 |
| Affected versions | RouterOS long-term 6.42.11 and below, RouterOS stable 6.43.11 and below |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2019-02-20 |
| Discrepant sources | affected_versions: CVE.org → ['RouterOS long-term 6.42.11 and below, RouterOS stable 6.43.11 and below'], NVD CPE → ['< 6.42.12', '< 6.43.12'] |
What is the CVE-2019-3924 vulnerability?
CVE-2019-3924 is an intermediation vulnerability present in MikroTik RouterOS versions prior to 6.43.12 (stable) and 6.42.12 (long-term). The software executes user-defined network requests to both WAN and LAN clients. A remote unauthenticated attacker can exploit this weakness to bypass the router’s firewall or perform general network scanning.
Which RouterOS versions are vulnerable?
The vulnerable versions are RouterOS long-term 6.42.11 and earlier, and RouterOS stable 6.43.11 and earlier. There is a discrepancy between sources: CVE.org states “RouterOS long-term 6.42.11 and below, RouterOS stable 6.43.11 and below”, while NVD CPE reports “< 6.42.12” and “< 6.43.12”. The exact fixed version is not specified in the JSON, but the description implies that versions 6.42.12 and 6.43.12 resolve the issue.
Is my router at risk?
A router is at risk if it runs RouterOS long-term 6.42.11 or earlier, or stable 6.43.11 or earlier. The vulnerability allows a remote unauthenticated attacker to send network requests to WAN and LAN clients, which implies that the router must be reachable from untrusted networks to be exploited. No specific services are listed as involved, but the nature of the vulnerability (execution of user-defined network requests) suggests that any service allowing such interaction could be a vector.
Is the CVE-2019-3924 vulnerability actively exploited?
As of the date of the article, there is no evidence that CVE-2019-3924 is being actively exploited. It is not present in the CISA KEV catalog and ENISA does not report it as exploited.
How to protect the router from CVE-2019-3924?
The primary action is to update RouterOS to a version later than 6.42.12 (long-term) or 6.43.12 (stable). No specific mitigations from the vendor are available in the JSON, but updating is the recommended solution.
Which RouterOS commands are needed to mitigate CVE-2019-3924?
Update RouterOS
The only definitive fix is the update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score of CVE-2019-3924?
CVE-2019-3924 has a CVSS v3.1 score of 7.5, classified as HIGH, with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.
Does CVE-2019-3924 require authentication to be exploited?
No, CVE-2019-3924 can be exploited by a remote unauthenticated attacker, as indicated in the vulnerability description.
Which RouterOS versions fix CVE-2019-3924?
The versions that fix CVE-2019-3924 are 6.42.12 (long-term) and 6.43.12 (stable), as versions prior to these are vulnerable.
Is CVE-2019-3924 listed in the CISA KEV catalog?
No, CVE-2019-3924 is not listed in the CISA KEV catalog and is not known to be actively exploited.



