CVE CVE-2018-1158
Severity not yet disclosed
Weakness CWE-674
Affected versions < 6.40.9, < 6.42.7
First non-vulnerable version 6.40.9, 6.42.7 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2018-08-23

What is the CVE-2018-1158 vulnerability?

CVE-2018-1158 is a stack exhaustion vulnerability in MikroTik RouterOS that allows a remote authenticated attacker to crash the HTTP server through recursive JSON parsing. The underlying weakness is classified as Uncontrolled Recursion (CWE-674).

Which RouterOS versions are vulnerable?

The vulnerable versions are those prior to 6.40.9 and 6.42.7. The exact corrective version is not specified in the available data, but upgrading to a release later than these thresholds resolves the issue.

Is my router at risk?

A router is at risk if it runs a RouterOS version prior to 6.40.9 or 6.42.7 and the web management service (WebFig) is active and reachable from untrusted networks. If the web service is disabled or accessible exclusively from the management network, the risk exposure is reduced.

Is the CVE-2018-1158 vulnerability actively exploited?

As of the date of the article, CVE-2018-1158 is not listed in the CISA KEV catalog nor reported as exploited by ENISA. There is no evidence of active exploitation.

How to protect the router from CVE-2018-1158?

Update RouterOS to a version later than 6.40.9 or 6.42.7 to eliminate the vulnerability. Alternatively, disable the web management service if not needed, or configure it so that it is reachable only from the trusted management network.

Which RouterOS commands are needed to mitigate CVE-2018-1158?

Temporary mitigation: www service

The defect concerns the web management service (WebFig). If you do not use it, turn it off; if you do use it, it must be reachable only from the management network.

# quali servizi di gestione sono attivi e da dove sono raggiungibili
/ip service print
# se WebFig non serve: spegnilo
/ip service set www disabled=yes
/ip service set www-ssl disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set www address=192.168.88.0/24
/ip service set www-ssl address=192.168.88.0/24

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2018-1158 require authentication to be exploited?

Yes, CVE-2018-1158 requires the attacker to be authenticated on the device to cause the HTTP server crash.

What is the minimum RouterOS version that fixes CVE-2018-1158?

The vulnerable versions are those prior to 6.40.9 and 6.42.7, so upgrading to a release later than these versions fixes the vulnerability.

Is disabling the web service enough to mitigate CVE-2018-1158?

Yes, disabling the web management service (WebFig) eliminates the attack vector, as the vulnerability resides in the JSON parsing by the HTTP server.

Official sources