CVE CVE-2018-1159
Severity not yet disclosed
Weakness CWE-119
Affected versions < 6.40.9, < 6.42.7
First non-vulnerable version 6.40.9, 6.42.7 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2018-08-23

What is the CVE-2018-1159 vulnerability?

CVE-2018-1159 is a memory corruption vulnerability (CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer) present in MikroTik RouterOS. A remote authenticated attacker can cause the HTTP server to crash by authenticating and disconnecting rapidly.

Which RouterOS versions are vulnerable?

The vulnerable versions are those prior to 6.40.9 and 6.42.7. The exact corrective version is not specified in the available data, but upgrading to a release later than these two resolves the issue.

Is my router at risk?

Your router is at risk if it is running a RouterOS version prior to 6.40.9 or 6.42.7 and the web management service (WebFig) is active and reachable from untrusted networks. If the web service is disabled or accessible only from the management network, the risk is reduced.

Is the CVE-2018-1159 vulnerability actively exploited?

As of the date of the article, CVE-2018-1159 is not listed in the CISA KEV catalog nor reported as exploited by ENISA.

How to protect the router from CVE-2018-1159?

Update RouterOS to a version later than 6.40.9 or 6.42.7. Alternatively, disable the web management service if not needed, or restrict its access exclusively to the trusted management network.

Which RouterOS commands are needed to mitigate CVE-2018-1159?

Temporary mitigation: www service

The defect concerns the web management service (WebFig). If you do not use it, turn it off; if you do use it, it must be reachable only from the management network.

# quali servizi di gestione sono attivi e da dove sono raggiungibili
/ip service print
# se WebFig non serve: spegnilo
/ip service set www disabled=yes
/ip service set www-ssl disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set www address=192.168.88.0/24
/ip service set www-ssl address=192.168.88.0/24

Updating RouterOS

The only definitive fix is the update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2018-1159 require authentication?

Yes, CVE-2018-1159 requires the attacker to be authenticated on the router to cause the HTTP server crash.

Which RouterOS version fixes CVE-2018-1159?

The vulnerability is present in versions prior to 6.40.9 and 6.42.7; upgrading to a release later than these resolves the issue.

Is disabling WebFig enough to protect against CVE-2018-1159?

Yes, disabling the web management service eliminates the attack surface for this vulnerability, as the crash occurs via the HTTP server.

Is CVE-2018-1159 in the CISA KEV catalog?

No, as of the date of the article, CVE-2018-1159 is not included in the CISA KEV catalog.

Official sources