| CVE | CVE-2019-3978 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 |
| Weakness | CWE-306 |
| Affected versions | RouterOS 6.45.6 Stable and below. RouterOS 6.44.5 Long-term and below. |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2019-10-29 |
What is the CVE-2019-3978 vulnerability?
The vulnerability allows unauthenticated remote attackers to trigger DNS queries via port 8291, sending requests from the router to an attacker-chosen server. The received DNS responses are stored in the router’s cache, which can lead to cache poisoning.
Which RouterOS versions are vulnerable?
The affected versions are RouterOS 6.45.6 Stable and all earlier versions, along with RouterOS 6.44.5 Long-term and all earlier versions. The specific fixed version has not yet been announced in the available data.
Is my router at risk?
A router is exposed if the DNS service is active and reachable from untrusted networks, such as the WAN. If the router does not act as a DNS server for the internal network, remote requests must be disabled. If it does provide internal DNS services, it is essential to block access to the service from the external network.
Is the CVE-2019-3978 vulnerability actively exploited?
As of the date of the article, there is no evidence that the vulnerability is being actively exploited. It is not present in the CISA KEV catalog, and ENISA does not report it as subject to known exploitation.
How to protect the router from CVE-2019-3978?
The primary mitigation is to update RouterOS to a version later than the affected ones. Alternatively, you can block access to the DNS service (port 8291) from untrusted networks via firewall configurations, ensuring that only authorized internal clients can send queries to the router’s resolver.
Which RouterOS commands are needed to mitigate CVE-2019-3978?
Temporary mitigation: dns service
The defect concerns the router’s DNS resolver. If it does not act as a DNS server for the internal network, remote requests must be disabled; if it does, they must be blocked from the WAN.
/ip dns print
# se il router non fa da DNS ai client
/ip dns set allow-remote-requests=no
# se lo fa: blocca le richieste DNS che arrivano da internet
/ip firewall filter add chain=input in-interface-list=WAN protocol=udp dst-port=53 \
action=drop place-before=0 comment="no DNS da WAN"
Update RouterOS
The only definitive fix is the update. Save the configuration first; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2019-3978?
The CVSS v3.1 score assigned to CVE-2019-3978 is 7.5, with HIGH severity. The vector indicates a network attack with low complexity, no authentication or user interaction required, and high impact on integrity.
Is authentication required to exploit CVE-2019-3978?
No, CVE-2019-3978 can be exploited by unauthenticated remote attackers. The underlying weakness is classified as “Missing Authentication for Critical Function” (CWE-306), indicating the absence of authentication controls for a critical function.
Which RouterOS versions fix CVE-2019-3978?
The vulnerable versions are RouterOS 6.45.6 Stable and earlier, and RouterOS 6.44.5 Long-term and earlier. The exact corrective version has not yet been disclosed in the available data, but upgrading to a release later than these is the recommended solution.
Is it possible to mitigate CVE-2019-3978 without updating the firmware?
Yes, you can mitigate the risk by blocking access to the DNS service (port 8291) from untrusted networks. If the router should not act as a DNS server for the internal network, remote requests must be disabled; if it does, access from the WAN must be blocked via the firewall.



