CVE CVE-2022-34960
Severity CRITICAL · CVSS 3.1 9.8
Weakness CWE-59
Affected versions not yet disclosed
Fixed version not yet disclosed
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2022-08-25

What is the CVE-2022-34960 vulnerability?

The vulnerability allows an attacker to create mount points that point to symbolic links, which resolve to locations on the host device. This mechanism enables the attacker to mount any arbitrary file at any location in the router’s operating system. The underlying weakness is classified as “Improper Link Resolution Before File Access (‘Link Following’)”.

Which RouterOS versions are vulnerable?

The vulnerability description specifies that the defect is present in the container package of MikroTik RouterOS 7.4beta4. The affected versions and the exact fixed version have not been explicitly disclosed in the available data, although version 7.4beta4 is identified as affected.

Is my router at risk?

Your router is at risk only if you have installed the container package and enabled it in device-mode. If you do not use the container service or if it is not active, the device is not exposed to this specific vulnerability. The risk condition requires that the service is active and reachable from untrusted networks.

Is the CVE-2022-34960 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of active exploitation in real-world environments.

How to protect the router from CVE-2022-34960?

The primary protection is to update RouterOS to a version that fixes the defect in the container package. If it is not possible to update immediately or if the service is not required, the mitigation is to completely disable the container package to eliminate the attack surface.

Which RouterOS commands are needed to mitigate CVE-2022-34960?

Temporary mitigation: container service

The defect concerns the container package. It only affects those who have installed and enabled it in device-mode; if you do not use it, disable it.

/system package print where name=container
/container print
# se non usi container: disattiva il pacchetto (richiede un riavvio)
/system package disable container

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2022-34960 require authentication to be exploited?

No, the CVSS 3.1 vector indicates “PR:N” (Privileges Required: None), which means the attack can be launched without authentication credentials.

What is the CVSS score of CVE-2022-34960?

The CVSS v3.1 score assigned by NVD is 9.8, classified as CRITICAL, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Is disabling the container package enough to mitigate CVE-2022-34960?

Yes, since the vulnerability specifically affects the container package in device-mode, disabling it eliminates exposure to this specific flaw.

Is CVE-2022-34960 in the CISA KEV catalog?

No, the vulnerability is not included in the CISA Known Exploited Vulnerabilities catalog and there is no evidence of active exploitation.

Official sources