| CVE | CVE-2019-3977 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 |
| Weakness | CWE-494 |
| Affected versions | RouterOS 6.45.6 Stable and below. RouterOS 6.44.5 Long-term and below. |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2019-10-29 |
What is the CVE-2019-3977 vulnerability?
The vulnerability consists of insufficient validation of the source from which update packages are downloaded when using the autoupgrade feature. A remote attacker can trick the router into believing it is performing an upgrade, causing it to install an older version of RouterOS instead. This behavior can lead to the reset of all system users and passwords.
Which RouterOS versions are vulnerable?
RouterOS 6.45.6 Stable and earlier versions, as well as RouterOS 6.44.5 Long-term and earlier versions, are vulnerable. The fixed version has not yet been announced.
Is my router at risk?
A router is exposed if the autoupgrade feature is enabled and the device is reachable from untrusted networks. Since the involved services are not specified, the risk depends on the configuration of the automatic update feature and the router’s exposure to uncontrolled traffic.
Is the CVE-2019-3977 vulnerability actively exploited?
As of the date of the article, the vulnerability is not present in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of active exploitation.
How to protect the router from CVE-2019-3977?
Disable the autoupgrade feature to prevent the router from downloading packages from unverified sources. If possible, update the firmware to a version later than those listed as vulnerable. Verify that the router is not reachable from untrusted networks unless strictly necessary.
Which RouterOS commands are needed to mitigate CVE-2019-3977?
Updating RouterOS
The only definitive fix is the update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score of CVE-2019-3977?
The CVSS v3.1 score of CVE-2019-3977 is 7.5, with HIGH severity. The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N.
Does CVE-2019-3977 require authentication to be exploited?
No, CVE-2019-3977 does not require authentication. The CVSS vector indicates PR:N (Privileges Required: None), which means the attack can be launched without credentials.
Which RouterOS versions fix CVE-2019-3977?
The fixed version for CVE-2019-3977 has not yet been announced. Versions 6.45.6 Stable and 6.44.5 Long-term, along with all earlier versions, remain vulnerable.
Does disabling autoupgrade eliminate the risk of CVE-2019-3977?
Yes, disabling the autoupgrade feature eliminates the specific attack vector of CVE-2019-3977, as the vulnerability manifests exclusively during the download of update packages via this feature.



