| CVE | CVE-2018-1156 |
|---|---|
| Severity | not yet disclosed |
| Weakness | CWE-787 |
| Affected versions | < 6.40.9, < 6.42.7 |
| First non-vulnerable version | 6.40.9, 6.42.7 (per branch) |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2018-08-23 |
What is the CVE-2018-1156 vulnerability?
CVE-2018-1156 describes a stack buffer overflow condition in the RouterOS license update interface. The underlying weakness is classified as Out-of-bounds Write (CWE-787). According to the description, this vulnerability could theoretically allow a remote authenticated attacker to execute arbitrary code on the system.
Which RouterOS versions are vulnerable?
RouterOS versions lower than 6.40.9 and lower than 6.42.7 are vulnerable. The exact fixed versions are not specified in the provided data, but updating must bring the system at least to versions 6.40.9 and 6.42.7 to eliminate the vulnerability.
Is my router at risk?
A router is at risk if it runs a RouterOS version lower than 6.40.9 or lower than 6.42.7 and if the license update interface is reachable by an authenticated attacker. Since the vulnerability requires authentication, the risk is limited to scenarios where valid credentials are available to a malicious user.
Is the CVE-2018-1156 vulnerability actively exploited?
As of the date of the article, CVE-2018-1156 is not listed in the CISA KEV catalog nor reported as exploited by ENISA. There is no evidence of known active exploitation.
How to protect the router from CVE-2018-1156?
The primary measure is to update RouterOS to a version equal to or higher than 6.40.9 or 6.42.7, depending on the release tree used. Alternatively, if updating is not immediately possible, it is advisable to limit access to the router management interface only from trusted networks and ensure that authenticated user credentials are protected and not shared.
Which RouterOS commands are needed to mitigate CVE-2018-1156?
Update RouterOS
The only definitive fix is the update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
Does CVE-2018-1156 require authentication to be exploited?
Yes, CVE-2018-1156 requires the attacker to be authenticated on the system to exploit the vulnerability in the license update interface.
What is the CVSS score of CVE-2018-1156?
The CVSS score has not been disclosed in the available data for this vulnerability.
Is disabling the license update interface enough to mitigate CVE-2018-1156?
It is not specified whether disabling the license update interface is an effective mitigation; the only recommended action is updating the firmware to the fixed versions.
Is CVE-2018-1156 present in the CISA KEV catalog?
No, CVE-2018-1156 is not included in the CISA KEV catalog as of the date of the article.
Official sources
- https://mikrotik.com/download/changelogs
- https://mikrotik.com/download/changelogs/bugfix-release-tree
- https://www.tenable.com/security/research/tra-2018-21
- https://mikrotik.com/download/changelogs
- https://mikrotik.com/download/changelogs/bugfix-release-tree
- https://www.tenable.com/security/research/tra-2018-21



