| CVE | CVE-2021-41987 |
|---|---|
| Severity | HIGH · CVSS 3.1 8.1 |
| Weakness | CWE-787 |
| Affected versions | not yet announced |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2022-03-16 |
What is the CVE-2021-41987 vulnerability?
CVE-2021-41987 is a heap-based buffer overflow in the SCEP server of RouterOS that allows an attacker to execute remote code. The attack requires the attacker to know the value of scep_server_name. The underlying weakness is classified as “Out-of-bounds Write” (CWE-787).
Which RouterOS versions are vulnerable?
The RouterOS versions affected by CVE-2021-41987 are 6.46.8, 6.47.9, and 6.47.10. The specific fixed version is not indicated in the available data, but upgrading to a release later than those listed is recommended.
Is my router at risk?
A router is exposed to CVE-2021-41987 if it is running one of the vulnerable versions (6.46.8, 6.47.9, or 6.47.10) and the SCEP service is active and reachable from untrusted networks. If the SCEP service is not configured or not accessible from outside, the risk is reduced.
Is the CVE-2021-41987 vulnerability actively exploited?
As of the date of this article, CVE-2021-41987 is not present in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of known active exploitation.
How to protect the router from CVE-2021-41987?
Update RouterOS to a version later than 6.46.8, 6.47.9, and 6.47.10. If the update is not immediate, disable the SCEP service if it is not strictly necessary. Verify that the service is not reachable from untrusted networks via firewall configurations.
Which RouterOS commands are needed to mitigate CVE-2021-41987?
Update RouterOS
The only definitive fix is the update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2021-41987?
CVE-2021-41987 has a CVSS v3.1 score of 8.1, classified as HIGH. The vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.
Does CVE-2021-41987 require authentication to be exploited?
No, CVE-2021-41987 does not require authentication (PR:N in the CVSS vector). However, the attacker must know the value of scep_server_name.
Which RouterOS versions fix CVE-2021-41987?
The vulnerable versions are 6.46.8, 6.47.9, and 6.47.10. The exact fixed version is not specified in the provided data, but any release later than these should resolve the issue.
Is CVE-2021-41987 in the CISA KEV catalog?
No, CVE-2021-41987 is not present in the CISA KEV catalog as of the date of this article. It is therefore not listed as an actively exploited vulnerability according to CISA criteria.
What type of weakness is CVE-2021-41987?
CVE-2021-41987 is an “Out-of-bounds Write” (CWE-787) vulnerability, which in this case manifests as a heap-based buffer overflow in the SCEP server.



