CVE CVE-2019-13954
Severity not yet disclosed
Weakness CWE-770
Affected versions < 6.44.5
First non-vulnerable version 6.44.5 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2019-07-26

What is the CVE-2019-13954 vulnerability?

CVE-2019-13954 is a memory exhaustion flaw that allows a remote authenticated attacker to crash the HTTP server by sending a specially crafted HTTP request. In some cases, this can lead to a system reboot, but it does not allow for the injection of malicious code.

Which RouterOS versions are vulnerable?

RouterOS versions prior to 6.44.5 are vulnerable. The specific corrective version was not disclosed in the database, but updating to a version later than 6.44.5 resolves the issue.

Is my router at risk?

Your router is at risk if the web management service (WebFig) is active and reachable from untrusted networks. If the web service is not used, it should be disabled. If it is used, it must be accessible only from the trusted administration network.

Is the CVE-2019-13954 vulnerability actively exploited?

As of the date of this article, the vulnerability is not known to be actively exploited and is not present in the CISA KEV catalog.

How to protect the router from CVE-2019-13954?

The primary solution is to update RouterOS to a version later than 6.44.5. Alternatively, if the web service is not required, it should be disabled. If the web service is required, access must be restricted to the trusted administration network only.

Which RouterOS commands are needed to mitigate CVE-2019-13954?

Temporary mitigation: www service

The flaw affects the web management service (WebFig). If you do not use it, turn it off; if you do use it, it must be reachable only from the administration network.

# quali servizi di gestione sono attivi e da dove sono raggiungibili
/ip service print
# se WebFig non serve: spegnilo
/ip service set www disabled=yes
/ip service set www-ssl disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set www address=192.168.88.0/24
/ip service set www-ssl address=192.168.88.0/24

Update RouterOS

The only definitive fix is an update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2019-13954 require authentication to be exploited?

Yes, CVE-2019-13954 requires the attacker to be authenticated on the router to send the malicious HTTP requests that cause the server crash.

Which RouterOS version fixes CVE-2019-13954?

Version 6.44.5 is indicated as the lower bound of vulnerable versions, so versions later than 6.44.5 are not affected by this specific vulnerability.

Does disabling the web service eliminate the risk of CVE-2019-13954?

Yes, disabling the web management service (WebFig) eliminates the attack vector for CVE-2019-13954, as the vulnerability is exploited exclusively through requests to the HTTP server.

Does CVE-2019-13954 allow arbitrary code execution?

No, the vulnerability description clearly states that CVE-2019-13954 does not allow the injection of malicious code, limiting the impact to a server crash and a possible system reboot.

Official sources