CVE CVE-2019-15055
Severity not yet disclosed
Weakness CWE-22
Affected versions not yet disclosed
Fixed version not yet disclosed
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2019-08-26

What is the CVE-2019-15055 vulnerability?

CVE-2019-15055 concerns improper disk name handling in MikroTik RouterOS, allowing authenticated users to delete arbitrary files. By exploiting this weakness, an attacker can reset the credential storage, thereby gaining access to the management interface as an administrator without the need for authentication. The associated CWE classification is “Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)”.

Which RouterOS versions are vulnerable?

The description indicates that versions up to 6.44.5 and 6.45.x versions up to 6.45.3 are vulnerable. The specific fixed version has not yet been disclosed in the available data, but releases subsequent to those listed as affected should contain the fix.

Is my router at risk?

A router is exposed if it is running one of the indicated vulnerable versions (up to 6.44.5 or 6.45.x up to 6.45.3) and if an authenticated user has access to the system. Since the attack requires authentication, the risk is higher in environments where privileged accounts are shared or where network access is not sufficiently controlled.

Is the CVE-2019-15055 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog nor reported as exploited by ENISA. There is no evidence of documented active exploitation in the available sources.

How to protect the router from CVE-2019-15055?

The primary measure is to update the RouterOS firmware to a version later than the vulnerable releases (6.44.5 and 6.45.3). Pending the update, it is advisable to restrict access to the management interface to trusted networks only and to verify that no unnecessary authenticated accounts with elevated privileges exist.

Which RouterOS commands are needed to mitigate CVE-2019-15055?

Update RouterOS

The only definitive fix is the update. First, save the configuration; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2019-15055 require authentication to be exploited?

Yes, CVE-2019-15055 allows authenticated users to delete arbitrary files, so the attack assumes already authenticated access to the system.

What is the CVSS score for CVE-2019-15055?

The CVSS score has not yet been disclosed in the available data for this vulnerability.

Is CVE-2019-15055 in the CISA KEV catalog?

No, CVE-2019-15055 is not listed in the CISA KEV catalog as of the date of the article.

Which RouterOS versions are affected by CVE-2019-15055?

The affected versions are those up to 6.44.5 and versions 6.45.x up to 6.45.3, as indicated in the vulnerability description.

Official sources