| CVE | CVE-2018-7445 |
|---|---|
| Severity | CRITICAL · CVSS 3.1 9.8 |
| Weakness | CWE-119 |
| Affected versions | < 6.41.3 |
| First non-vulnerable version | 6.41.3 (per branch) |
| Actively exploited | YES — CISA KEV catalog since 2022-09-08 |
| CISA Advisory | none |
| Published | 2018-03-19 |
What is the CVE-2018-7445 vulnerability?
This is a buffer overflow (CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer) present in the SMB service of RouterOS during the processing of NetBIOS session request messages. A remote attacker with access to the service can exploit the flaw to achieve code execution on the system. The overflow occurs before authentication, so an unauthenticated remote attacker can exploit it.
Which RouterOS versions are vulnerable?
All RouterOS versions prior to 6.41.3 are vulnerable. The exact corrective version is not specified in the available data, but the description indicates that devices running versions lower than 6.41.3/6.42rc27 are affected. Since 6.42rc27 is a development version (release candidate), stable releases prior to 6.41.3 remain vulnerable.
Is my router at risk?
A router is exposed if the SMB service (file sharing) is active and reachable from untrusted networks. Since the vulnerability is exploitable without authentication, even simple network access to the SMB service can lead to code execution. In production, the SMB service is rarely necessary and should be disabled unless strictly indispensable.
Is the CVE-2018-7445 vulnerability actively exploited?
Yes, the vulnerability is present in the CISA KEV (Known Exploited Vulnerabilities) catalog since 2022-09-08. CISA requires applying updates according to the vendor’s instructions.
How to protect the router from CVE-2018-7445?
Update RouterOS to a version later than 6.41.3. If the update is not immediately possible, disable the SMB service on the router, as the vulnerability is exploitable only through that service. Verify that the SMB service is not reachable from external or untrusted networks.
Which RouterOS commands are needed to mitigate CVE-2018-7445?
Temporary mitigation: smb service
The flaw concerns the router’s SMB file sharing server, which almost no one uses in production: it must be turned off.
/ip smb print
/ip smb set enabled=no
Update RouterOS
The only definitive fix is the update. Save the configuration first; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score of CVE-2018-7445?
CVE-2018-7445 has a CVSS v3.1 score of 9.8 (CRITICAL), with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a high risk to the confidentiality, integrity, and availability of the system.
Is authentication required to exploit CVE-2018-7445?
No, CVE-2018-7445 is exploitable without authentication. The overflow occurs during the processing of NetBIOS messages before any credentials are requested.
Which RouterOS version fixes CVE-2018-7445?
The description indicates that versions prior to 6.41.3 are vulnerable. The specific corrective version is not detailed in the provided data, but updating to a version later than 6.41.3 is necessary to resolve the issue.
Is CVE-2018-7445 in the CISA KEV catalog?
Yes, CVE-2018-7445 has been included in the CISA KEV catalog since 2022-09-08, with the requirement to apply updates according to the vendor’s instructions.
Is disabling the SMB service enough to mitigate CVE-2018-7445?
Yes, since the vulnerability exists exclusively in the SMB service, disabling it removes the attack surface for this specific vulnerability. However, updating the firmware remains the recommended definitive solution.
Official sources
- http://seclists.org/fulldisclosure/2018/Mar/38
- http://www.securityfocus.com/bid/103427
- https://www.coresecurity.com/advisories/mikrotik-routeros-smb-buffer-overflow
- https://www.exploit-db.com/exploits/44290/
- http://seclists.org/fulldisclosure/2018/Mar/38
- http://www.securityfocus.com/bid/103427
- https://www.coresecurity.com/advisories/mikrotik-routeros-smb-buffer-overflow
- https://www.exploit-db.com/exploits/44290/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7445



