| CVE | CVE-2020-5721 |
|---|---|
| Severity | MEDIUM · CVSS 3.1 5.5 |
| Weakness | CWE-260, CWE-522 |
| Affected versions | 3.22 and below |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2020-04-15 |
What is the CVE-2020-5721 vulnerability?
CVE-2020-5721 is a flaw that allows an attacker with access to the settings.cfg.viw configuration file to extract the username and password in clear text to gain access to the router. This occurs because WinBox 3.22 and earlier versions save the password in unencrypted text when the “Keep Password” option is enabled and no Master Password is set. Since “Keep Password” is enabled by default and the Master Password is not set, the vulnerable condition exists in standard installations.
Which RouterOS versions are vulnerable?
The vulnerable versions are WinBox 3.22 and all previous versions. The fixed version has not yet been announced.
Is my router at risk?
A router is exposed if an attacker manages to gain access to the settings.cfg.viw configuration file of the WinBox client used for management. The flaw affects WinBox, both via IP and via MAC address, and requires that the attacker already has access to the operating system or local files where the client resides. This is not a direct network exposure, but a compromise of locally saved credentials.
Is the CVE-2020-5721 vulnerability actively exploited?
As of the date of the article, there is no evidence that the vulnerability is being exploited. It is not present in the CISA KEV catalog and ENISA does not report it as exploited.
How to protect the router from CVE-2020-5721?
Update WinBox to a version later than 3.22 to eliminate the saving of the password in clear text. Alternatively, disable the “Keep Password” option in the WinBox settings or set a Master Password to protect the saved credentials. Restrict access to the client configuration files and ensure that only authorized users can access the operating system where WinBox is installed.
Which RouterOS commands are needed to mitigate CVE-2020-5721?
Temporary mitigation: winbox service
The flaw affects Winbox, both via IP and via MAC address. Both access methods must be restricted to the management network.
/ip service print
# Winbox via IP solo dalla rete di gestione (sostituisci con la tua)
/ip service set winbox address=192.168.88.0/24
# Winbox via MAC: spegnilo, o limitalo a un'interface-list di gestione
/tool mac-server mac-winbox set allowed-interface-list=none
Update RouterOS
The only definitive fix is the update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score of CVE-2020-5721?
The CVSS v3.1 score of CVE-2020-5721 is 5.5, with MEDIUM severity. The vector indicates a local attack with low complexity, low privileges required, and no user input necessary.
Which weaknesses (CWE) are associated with CVE-2020-5721?
CVE-2020-5721 is associated with the weaknesses CWE-260 (Password in Configuration File) and CWE-522 (Insufficiently Protected Credentials).
Is authentication required to exploit CVE-2020-5721?
Yes, the attacker must have access to the WinBox client configuration file settings.cfg.viw. A remote network attack is not required, but local or privileged access to the system where the client is installed is needed.
Does the Master Password protect against CVE-2020-5721?
Yes, setting a Master Password in WinBox prevents the password from being saved in plain text in the configuration file, mitigating the vulnerability.



