| CVE | CVE-2008-0680 |
|---|---|
| Severity | not yet disclosed |
| Weakness | not yet disclosed |
| Affected versions | not yet disclosed |
| Fixed version | not yet disclosed |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2008-02-12 |
What is the CVE-2008-0680 vulnerability?
The CVE-2008-0680 vulnerability affects the SNMPd component in MikroTik RouterOS 3.2 and earlier versions. It allows a remote attacker to cause a denial of service (daemon crash) by sending a specially crafted SNMP SET request.
Which RouterOS versions are vulnerable?
The vulnerable versions are MikroTik RouterOS 3.2 and all earlier versions. The specific fixed version is not yet disclosed in the available data, but upgrading to a release later than 3.2 resolves the issue.
Is my router at risk?
A router is at risk if it runs MikroTik RouterOS version 3.2 or earlier and has the SNMP service active and reachable from untrusted networks. If the SNMP service is disabled or the router is not exposed to external traffic, the risk is reduced.
Is the CVE-2008-0680 vulnerability actively exploited?
As of the date of the article, the CVE-2008-0680 vulnerability is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of active exploitation.
How to protect the router from CVE-2008-0680?
The primary measure is to upgrade RouterOS to a version later than 3.2. Alternatively, if the SNMP service is not required for network monitoring, it should be completely disabled to eliminate the attack surface.
Which RouterOS commands are needed to mitigate CVE-2008-0680?
Temporary mitigation: snmp service
The flaw concerns SNMP. If there is no monitoring system using it, it should be turned off.
/snmp set enabled=no
Upgrade RouterOS
The only definitive fix is the upgrade. Save the configuration first; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
Does CVE-2008-0680 require authentication to be exploited?
The vulnerability description indicates that a remote attacker can cause the SNMP daemon to crash via a malicious SET request, but it does not specify whether authentication is required. However, given that this is a denial of service via SNMP SET, it is likely that the attack exploits the ability to send SNMP packets without full authentication, depending on the configuration.
What is the CVSS score for CVE-2008-0680?
The CVSS v3.1 and v4.0 scores for CVE-2008-0680 are not yet disclosed in the available data.
Is disabling SNMP enough to protect against CVE-2008-0680?
Yes, disabling the SNMP service eliminates the specific attack surface for this vulnerability, as the flaw resides in the SNMPd daemon. If SNMP is not used for monitoring, disabling it is an effective mitigation.
Is CVE-2008-0680 present in the CISA KEV catalog?
No, CVE-2008-0680 is not present in the CISA KEV catalog and is not reported as being actively exploited according to available data.
Official sources
- http://hellknights.void.ru/shados/snmp_sploit.c
- http://secunia.com/advisories/28762
- http://www.securityfocus.com/bid/27599
- http://www.vupen.com/english/advisories/2008/0399
- https://www.exploit-db.com/exploits/5054
- http://hellknights.void.ru/shados/snmp_sploit.c
- http://secunia.com/advisories/28762
- http://www.securityfocus.com/bid/27599
- http://www.vupen.com/english/advisories/2008/0399
- https://www.exploit-db.com/exploits/5054



