CVE CVE-2019-13074
Severity not yet disclosed
Weakness CWE-770
Affected versions not yet disclosed
Fixed version not yet disclosed
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2019-07-03

What is the CVE-2019-13074 vulnerability?

The vulnerability resides in the FTP daemon and allows a remote attacker to exhaust all available memory on the router. This behavior is due to uncontrolled resource consumption, which causes the device to reboot.

Which RouterOS versions are vulnerable?

The affected versions are those up to and including 6.44.3. The specific fixed version has not yet been disclosed in the available data.

Is my router at risk?

A router is exposed if the FTP service is active and reachable from untrusted networks. Since this is a legacy cleartext service, it should not be enabled on any modern router. If the FTP service is disabled or not accessible from outside, the risk is null.

Is the CVE-2019-13074 vulnerability actively exploited?

As of the date of the article, there is no evidence that the vulnerability is being exploited. It is not present in the CISA KEV catalog, and ENISA does not report it as exploited.

How to protect the router from CVE-2019-13074?

The primary mitigation is to update RouterOS to a version later than 6.44.3, if available. Alternatively, you must completely disable the FTP service on the device, as it should not be active in modern environments.

Which RouterOS commands are needed to mitigate CVE-2019-13074?

Temporary mitigation: legacy service

The defect concerns cleartext services (Telnet, FTP) that should not be active on any modern router.

/ip service set telnet disabled=yes
/ip service set ftp disabled=yes

Update RouterOS

The only definitive fix is the update. First, save the configuration; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Which RouterOS component does CVE-2019-13074 affect?

CVE-2019-13074 specifically affects the FTP daemon of RouterOS.

What is the CWE classification of CVE-2019-13074?

The vulnerability is classified as CWE-770, “Allocation of Resources Without Limits or Throttling”.

Is authentication required to exploit CVE-2019-13074?

The available data does not specify whether authentication is required to exploit the vulnerability.

What is the CVSS score of CVE-2019-13074?

The CVSS score has not yet been disclosed in the available data.

Official sources