CVE CVE-2022-45313
Severity HIGH · CVSS 3.1 8.8
Weakness CWE-125
Affected versions < 7.5
First non-vulnerable version 7.5 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2022-12-05

What is the CVE-2022-45313 vulnerability?

CVE-2022-45313 is an Out-of-bounds Read weakness present in the hotspot process of RouterOS. This vulnerability allows an attacker to execute arbitrary code by sending a specially crafted nova message to the router.

Which RouterOS versions are vulnerable?

The vulnerable RouterOS versions are all those prior to 7.5. The exact corrective version is not specified beyond the indication that the vulnerability is present in versions prior to 7.5, so updating to 7.5 or higher resolves the issue.

Is my router at risk?

A router is at risk if it runs a RouterOS version prior to 7.5 and has the hotspot service active and reachable from untrusted networks. If the hotspot service is disabled or the router is not exposed to untrusted external traffic, the risk of remote exploitation is reduced.

Is the CVE-2022-45313 vulnerability actively exploited?

As of the date of the article, CVE-2022-45313 is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of known active exploitation.

How to protect the router from CVE-2022-45313?

The primary action is to update RouterOS to a stable version later than 7.5. Alternatively, if the hotspot service is not required, disabling it reduces the attack surface. No specific mitigations are available from the vendor other than the update.

Which RouterOS commands are needed to mitigate CVE-2022-45313?

Update RouterOS

The only definitive fix is the update. First, save the configuration; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score of CVE-2022-45313?

The CVSS v3.1 score of CVE-2022-45313 is 8.8, classified as HIGH severity.

Which RouterOS version fixes CVE-2022-45313?

The CVE-2022-45313 vulnerability is present in RouterOS versions prior to 7.5; updating to 7.5 or higher eliminates the issue.

Is authentication required to exploit CVE-2022-45313?

Yes, the CVSS vector indicates that a low privilege level (PR:L) is required, so the attacker must have authenticated access to the router.

Does disabling the hotspot service eliminate the risk of CVE-2022-45313?

Yes, since the vulnerability resides in the hotspot process, disabling this service removes the specific attack vector for CVE-2022-45313.

Is CVE-2022-45313 in the CISA KEV catalog?

No, CVE-2022-45313 is not present in the CISA KEV catalog and is not reported as actively exploited according to available sources.

Official sources