| CVE | CVE-2023-30800 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 |
| Weakness | CWE-787 |
| Affected versions | 6.48.8, 6.49.9 |
| Fixed version | 6.49.10 |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2023-09-07 |
| Discrepant sources | affected_versions: CVE.org → ['6.48.8', '6.49.9'], NVD CPE → ['< 6.49.10'] |
What is the CVE-2023-30800 vulnerability?
The web server used by RouterOS version 6 has a heap memory corruption issue. A remote, unauthenticated attacker can corrupt the server’s heap memory by sending a specially crafted HTTP request. As a result, the web interface freezes and restarts immediately. The flaw is classified as “Out-of-bounds Write” (CWE-787).
Which RouterOS versions are vulnerable?
The versions specified as affected are 6.48.8 and 6.49.9. The fixed version is 6.49.10 stable. There is a discrepancy between sources: CVE.org lists versions 6.48.8 and 6.49.9, while NVD CPE indicates all versions lower than 6.49.10. RouterOS version 7 is not affected.
Is my router at risk?
A router is exposed if it runs a vulnerable version of RouterOS 6 and the management web service (WebFig) is active and reachable from untrusted networks. If the web interface is not used, it should be disabled. If it is used, it must be reachable exclusively from the management network.
Is the CVE-2023-30800 vulnerability actively exploited?
As of the date of the article, the vulnerability is not listed in the CISA KEV catalog, and ENISA does not report it as exploited. There is no evidence of active exploitation.
How to protect the router from CVE-2023-30800?
Update RouterOS to version 6.49.10 stable or higher. Alternatively, disable the management web service (WebFig) if not needed, or restrict its access exclusively to the management network to prevent reachability by remote attackers.
Which RouterOS commands are needed to mitigate CVE-2023-30800?
Temporary mitigation: www service
The flaw affects the management web service (WebFig). If you do not use it, turn it off; if you do use it, it must be reachable only from the management network.
# quali servizi di gestione sono attivi e da dove sono raggiungibili
/ip service print
# se WebFig non serve: spegnilo
/ip service set www disabled=yes
/ip service set www-ssl disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set www address=192.168.88.0/24
/ip service set www-ssl address=192.168.88.0/24
Update RouterOS
The only definitive fix is an update. Save the configuration first; the installation restarts the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score of CVE-2023-30800?
CVE-2023-30800 has a CVSS v3.1 score of 7.5, classified as HIGH severity. The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.
Is RouterOS version 7 vulnerable to CVE-2023-30800?
No, RouterOS version 7 is not affected by this vulnerability. The flaw exclusively affects the web server of RouterOS version 6.
What is the fixed version for CVE-2023-30800?
The corrective version is 6.49.10 stable. Versions 6.48.8 and 6.49.9 are listed as affected, although NVD CPE indicates all versions below 6.49.10.
Does exploiting CVE-2023-30800 require authentication?
No, the attack does not require authentication. A remote, unauthenticated attacker can crash the web interface by sending a malicious HTTP request.



