CVE CVE-2018-10070
Severity not yet disclosed
Weakness CWE-400
Affected versions not yet disclosed
Fixed version not yet disclosed
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2018-04-16

What is the CVE-2018-10070 vulnerability?

The vulnerability allows a remote unauthenticated attacker to exhaust all available CPU and RAM resources by sending a specific FTP request on port 21 that begins with many ‘\0’ characters. This prevents the router from accepting new FTP connections. After about 10 minutes, the router automatically reboots, logging the message “router was rebooted without proper shutdown”.

Which RouterOS versions are vulnerable?

The version specified as vulnerable is MikroTik Version 6.41.4. Fixed versions have not yet been disclosed in the available data.

Is my router at risk?

A router is at risk if it is running version 6.41.4 and has the FTP service active and reachable from untrusted networks. Since this is a cleartext service that should not be active on any modern router, the exposure depends on the device’s current configuration.

Is the CVE-2018-10070 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of active exploitation.

How to protect the router from CVE-2018-10070?

The primary mitigation is to update the firmware to a version later than 6.41.4, if available and stable. Alternatively, you can completely disable the FTP service if it is not essential for network operations, thereby eliminating the attack surface described.

Which RouterOS commands are needed to mitigate CVE-2018-10070?

Temporary mitigation: legacy service

The defect concerns cleartext services (Telnet, FTP) that should not be active on any modern router.

/ip service set telnet disabled=yes
/ip service set ftp disabled=yes

Update RouterOS

The only definitive fix is an update. Save the configuration first; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2018-10070 require authentication to be exploited?

No, CVE-2018-10070 allows a remote unauthenticated attacker to exploit the vulnerability by sending a malicious FTP request.

What is the type of weakness associated with CVE-2018-10070?

The associated weakness is CWE-400, defined as Uncontrolled Resource Consumption.

Does the router recover automatically after the attack described in CVE-2018-10070?

Yes, the router automatically reboots after about 10 minutes of resource exhaustion, logging an improper reboot message in the logs.

What is the CVSS score for CVE-2018-10070?

The CVSS score has not yet been disclosed in the available data.

Official sources