| CVE | CVE-2021-3014 |
|---|---|
| Severity | MEDIUM · CVSS 3.1 6.1 |
| Weakness | CWE-79 |
| Affected versions | not yet announced |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2021-01-04 |
What is the CVE-2021-3014 vulnerability?
The vulnerability consists of a reflected Cross-Site Scripting (XSS) in the login page of the Hotspot service. The attack occurs via the “target” parameter, which is not properly neutralized during web page generation. This weakness is classified as CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’).
Which RouterOS versions are vulnerable?
The affected versions are all RouterOS versions published up to January 4, 2021. The specific fixed version has not yet been announced in available sources.
Is my router at risk?
A router is exposed if the Hotspot service is active and its login page is reachable from untrusted networks. If Hotspot is not configured or if the login page is not accessible from the Internet or from uncontrolled network segments, the risk is reduced.
Is the CVE-2021-3014 vulnerability actively exploited?
As of the date of the article, there is no evidence that the vulnerability is being actively exploited. CISA does not include it in the KEV catalog, and ENISA does not report it as exploited.
How to protect the router from CVE-2021-3014?
The primary measure is to update the router firmware to a version later than January 4, 2021, which contains the fix for this vulnerability. Alternatively, if an update is not immediately possible, it is advisable to disable access to the Hotspot login page from untrusted networks or to restrict access to traffic only from trusted internal networks.
Which RouterOS commands are needed to mitigate CVE-2021-3014?
Update RouterOS
The only definitive fix is the update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2021-3014?
The CVSS v3.1 score assigned to CVE-2021-3014 is 6.1, with a severity classified as MEDIUM.
Does CVE-2021-3014 require authentication to be exploited?
No, CVE-2021-3014 does not require authentication by the attacker, as it is a reflected XSS on the login page. However, it requires user interaction (UI:R) to be executed.
Is the CVE-2021-3014 vulnerability present in the CISA KEV catalog?
No, CVE-2021-3014 is not present in the CISA KEV catalog, indicating that it is not known to be actively exploited in attacks.
What is the CWE weakness associated with CVE-2021-3014?
The CWE weakness associated with CVE-2021-3014 is CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’).
Official sources
- https://github.com/M4DM0e/m4dm0e.github.io/blob/gh-pages/_posts/2021-01-04-mikrotik-xss-reflected.md
- https://m4dm0e.github.io/2021/01/04/mikrotik-xss-reflected.html
- https://github.com/M4DM0e/m4dm0e.github.io/blob/gh-pages/_posts/2021-01-04-mikrotik-xss-reflected.md
- https://m4dm0e.github.io/2021/01/04/mikrotik-xss-reflected.html



