CVE CVE-2018-1157
Severity not yet disclosed
Weakness CWE-400
Affected versions < 6.40.9, < 6.42.7
First non-vulnerable version 6.40.9, 6.42.7 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2018-08-23

What is the CVE-2018-1157 vulnerability?

CVE-2018-1157 is a resource exhaustion flaw (CWE-400: Uncontrolled Resource Consumption) present in RouterOS versions prior to 6.40.9 and 6.42.7. An authenticated remote attacker can send a specially crafted HTTP POST request to crash the HTTP server; in some circumstances, this action also causes the system to reboot.

Which RouterOS versions are vulnerable?

RouterOS versions lower than 6.40.9 and lower than 6.42.7 are vulnerable. The exact fixed versions are not specified in the available data, but upgrading to a version later than these thresholds eliminates the vulnerability.

Is my router at risk?

Your router is at risk if it runs a RouterOS version earlier than 6.40.9 or 6.42.7 and the web management service (WebFig) is active and reachable from untrusted networks. If the web service is disabled or accessible only from the management network, the exposure is reduced, but upgrading remains the recommended measure.

Is the CVE-2018-1157 vulnerability actively exploited?

As of the date of this article, CVE-2018-1157 is not listed in the CISA KEV catalog nor reported as exploited by ENISA. There is no evidence of active exploitation.

How to protect the router from CVE-2018-1157?

The primary measure is to upgrade RouterOS to a version later than 6.40.9 or 6.42.7. Alternatively, if the web service is not required, it should be disabled. If in use, it must be configured to be reachable exclusively from the management network, blocking access from external or untrusted networks.

Which RouterOS commands are needed to mitigate CVE-2018-1157?

Temporary mitigation: www service

The flaw affects the web management service (WebFig). If you do not use it, turn it off; if you do use it, it must be reachable only from the management network.

# quali servizi di gestione sono attivi e da dove sono raggiungibili
/ip service print
# se WebFig non serve: spegnilo
/ip service set www disabled=yes
/ip service set www-ssl disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set www address=192.168.88.0/24
/ip service set www-ssl address=192.168.88.0/24

Upgrade RouterOS

The only definitive fix is the upgrade. Save the configuration first; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2018-1157 require authentication to be exploited?

Yes, CVE-2018-1157 requires the attacker to be authenticated on the device to send the malicious HTTP POST request.

What is the CVSS score for CVE-2018-1157?

The CVSS score has not been disclosed in the available data.

Is disabling the web service enough to mitigate CVE-2018-1157?

Yes, disabling the web management service (WebFig) eliminates the attack surface described in CVE-2018-1157, as the vulnerability is specifically linked to the HTTP server.

Is CVE-2018-1157 present in the CISA KEV catalog?

No, CVE-2018-1157 is not present in the CISA KEV catalog as of the date of the article.

Official sources