CVE CVE-2024-27686
Severity HIGH · CVSS 3.1 7.5
Weakness CWE-400
Affected versions not yet announced
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2026-05-08

What is the CVE-2024-27686 vulnerability?

CVE-2024-27686 is an “Uncontrolled Resource Consumption” flaw (CWE-400) that allows a remote attacker to cause a denial of service by crashing the device. The attack occurs by sending specifically crafted packet data to the SMB service, accessible on TCP port 445.

Which RouterOS versions are vulnerable?

The vulnerable versions are RouterOS releases for x86 between 6.40.5 and 6.49.10. The description indicates that the issue was resolved in the 7 series, but it does not specify an exact fixed version within the 7.x line. Versions 6.x later than 6.49.10 are not explicitly mentioned as fixed or vulnerable in the provided text.

Is my router at risk?

A router is at risk if it runs a RouterOS x86 version between 6.40.5 and 6.49.10, if the SMB service is active, and if TCP port 445 is reachable from untrusted networks. Since the SMB service is rarely used in production environments, the actual risk is limited to cases where this service has been explicitly enabled and exposed.

Is the CVE-2024-27686 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog, nor is it flagged by ENISA as exploited. There is no evidence of documented active exploitation in the provided sources.

How to protect the router from CVE-2024-27686?

The primary mitigation is to update the operating system to the RouterOS 7 series, where the flaw has been resolved. Alternatively, if an immediate update is not possible, you must completely disable the SMB service on the router to eliminate the attack surface. It is advisable to verify that TCP port 445 is not reachable from external or untrusted networks.

Which RouterOS commands are needed to mitigate CVE-2024-27686?

Temporary mitigation: smb service

The flaw affects the router’s SMB file-sharing server, which almost no one uses in production: turn it off.

/ip smb print
/ip smb set enabled=no

Update RouterOS

The only definitive fix is an update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2024-27686?

CVE-2024-27686 has a CVSS v3.1 score of 7.5, classified as HIGH severity. The vector indicates that the attack is remote, requires low complexity, does not require user privileges or user interaction, and has a high impact on availability.

Is authentication required to exploit CVE-2024-27686?

No, the CVE-2024-27686 vulnerability can be exploited by a remote attacker without the need for authentication, as indicated by the CVSS vector which specifies “PR:N” (Privileges Required: None).

Is disabling the SMB service sufficient to mitigate CVE-2024-27686?

Yes, disabling the SMB service eliminates the attack surface for CVE-2024-27686, since the flaw manifests exclusively through interaction with this specific service on TCP port 445.

Which RouterOS versions fix CVE-2024-27686?

The description indicates that the vulnerability was fixed in the RouterOS 7 series, but does not specify an exact numerical version within this line. Versions 6.40.5 through 6.49.10 for x86 are confirmed to be vulnerable.

Official sources