| CVE | CVE-2020-5720 |
|---|---|
| Severity | MEDIUM · CVSS 3.1 5.9 |
| Weakness | CWE-22 |
| Affected versions | All versions prior to version 3.21 |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2020-02-06 |
| Discrepant sources | affected_versions: CVE.org → ['All versions prior to version 3.21'], NVD CPE → ['< 3.21'] |
What is the CVE-2020-5720 vulnerability?
CVE-2020-5720 is a path traversal vulnerability (CWE-22: Improper Limitation of a Pathname to a Restricted Directory) that allows the creation of arbitrary files in any location where WinBox has write permissions. The attack occurs when WinBox connects to a malicious endpoint or when an attacker performs a man-in-the-middle attack on the connection.
Which RouterOS versions are vulnerable?
The vulnerable versions are all WinBox versions prior to 3.21. The fixed version is 3.21. There is a discrepancy between sources: CVE.org states “All versions prior to version 3.21” while NVD CPE reports “< 3.21”. Both indications converge on the fact that versions lower than 3.21 are affected.
Is my router at risk?
A router is exposed if the WinBox client used to manage it is a version prior to 3.21 and connects to untrusted endpoints or traverses networks where it might suffer man-in-the-middle attacks. The risk primarily concerns the environment in which the WinBox client operates, not necessarily the router itself, but compromising the client can lead to the creation of arbitrary files on the system running WinBox.
Is the CVE-2020-5720 vulnerability actively exploited?
As of the date of the article, CVE-2020-5720 is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of active exploitation.
How to protect the router from CVE-2020-5720?
Updating WinBox to version 3.21 or higher eliminates the vulnerability. Alternatively, restrict access to the WinBox service (both via IP and via MAC) exclusively from the trusted administration network, avoiding connections from untrusted networks or through insecure tunnels.
Which RouterOS commands are needed to mitigate CVE-2020-5720?
Temporary mitigation: winbox service
The defect concerns Winbox, both via IP and via MAC address. Both accesses must be restricted to the administration network.
/ip service print
# Winbox via IP solo dalla rete di gestione (sostituisci con la tua)
/ip service set winbox address=192.168.88.0/24
# Winbox via MAC: spegnilo, o limitalo a un'interface-list di gestione
/tool mac-server mac-winbox set allowed-interface-list=none
Update RouterOS
The only definitive fix is the update. First, save the configuration; the installation reboots the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score of CVE-2020-5720?
CVE-2020-5720 has a CVSS v3.1 score of 5.9 (MEDIUM), with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N, assigned by NVD.
Is authentication required to exploit CVE-2020-5720?
No, the CVSS vector indicates PR:N (Privileges Required: None), so authentication is not required to exploit the vulnerability.
Which version of WinBox fixes CVE-2020-5720?
WinBox version 3.21 fixes CVE-2020-5720. All versions prior to 3.21 are vulnerable.
Is CVE-2020-5720 in the CISA KEV catalog?
No, CVE-2020-5720 is not present in the CISA KEV catalog and is not known to be actively exploited.



