| CVE | CVE-2019-3981 |
|---|---|
| Severity | LOW · CVSS 3.1 3.7 |
| Weakness | CWE-300 |
| Affected versions | Winbox 3.20 and below. |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2020-01-14 |
| Discrepant sources | affected_versions: CVE.org → ['Winbox 3.20 and below.'], NVD CPE → ['< 3.20', '< 6.43'] |
What is the CVE-2019-3981 vulnerability?
CVE-2019-3981 is a “Channel Accessible by Non-Endpoint” weakness (CWE-300) that allows man-in-the-middle attacks against Winbox 3.20 and earlier versions. An attacker can force a downgrade of the client’s authentication protocol to retrieve the user’s username and the password hashed with MD5.
Which RouterOS versions are vulnerable?
Available sources report a discrepancy regarding the affected versions: CVE.org states “Winbox 3.20 and below”, while NVD CPE lists “< 3.20” and “< 6.43”. The fixed version has not yet been announced.
Is my router at risk?
A router is exposed if the Winbox service is active and reachable from untrusted networks, either via IP address or via MAC address. To reduce exposure, both methods of accessing Winbox must be restricted to the internal administration network.
Is the CVE-2019-3981 vulnerability actively exploited?
As of the date of this article, the vulnerability is not listed in the CISA KEV catalog and is not reported as exploited by ENISA.
How to protect the router from CVE-2019-3981?
The primary mitigation is to update Winbox to a version later than 3.20, as the specific fixed version has not yet been announced. Alternatively or additionally, you must restrict access to the Winbox service (both via IP and via MAC) exclusively to the administration network, preventing reachability from external or untrusted networks.
Which RouterOS commands are needed to mitigate CVE-2019-3981?
Temporary mitigation: winbox service
The flaw affects Winbox, both via IP and via MAC address. Both access methods must be restricted to the administration network.
/ip service print
# Winbox via IP solo dalla rete di gestione (sostituisci con la tua)
/ip service set winbox address=192.168.88.0/24
# Winbox via MAC: spegnilo, o limitalo a un'interface-list di gestione
/tool mac-server mac-winbox set allowed-interface-list=none
Update RouterOS
The only definitive fix is an update. Save the configuration first; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2019-3981?
The CVSS v3.1 score assigned to CVE-2019-3981 is 3.7, with LOW severity, according to NVD.
Does CVE-2019-3981 require authentication to be exploited?
No, the CVSS vector indicates PR:N (Privileges Required: None), which means the attack does not require pre-existing credentials, but it requires a high complexity condition (AC:H) typical of man-in-the-middle attacks.
Which services are involved in CVE-2019-3981?
CVE-2019-3981 specifically concerns the Winbox client, whether access occurs via IP address or via MAC address.
Is the CVE-2019-3981 vulnerability in the CISA KEV catalog?
No, CVE-2019-3981 is not present in the CISA Known Exploited Vulnerabilities (KEV) catalog.



