| CVE | CVE-2023-32154 |
|---|---|
| Severity | not yet disclosed |
| Weakness | CWE-787 |
| Affected versions | 6.49.7 Stable |
| Fixed version | not yet disclosed |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2024-05-03 |
| Discrepant sources | affected_versions: CVE.org → ['6.49.7 Stable'], NVD CPE → ['< 6.48.7'] |
What is the CVE-2023-32154 vulnerability?
CVE-2023-32154 is an Out-of-bounds Write vulnerability in the Router Advertisement Daemon that allows attackers on the local network to execute arbitrary code with root privileges. The flaw stems from the lack of validation of user-supplied data, which causes a write beyond the end of an allocated buffer. Authentication is not required to exploit this vulnerability.
Which RouterOS versions are vulnerable?
Available sources report a discrepancy regarding affected versions: CVE.org lists “6.49.7 Stable”, while NVD CPE lists “< 6.48.7”. The fixed version has not yet been disclosed.
Is my router at risk?
A router is exposed if the RADVD service is active and reachable from untrusted networks, as the vulnerability allows code execution without authentication. There is no specific information on which RouterOS services are involved other than RADVD.
Is the CVE-2023-32154 vulnerability actively exploited?
As of the date of this article, there is no evidence that the vulnerability is being actively exploited. CISA does not include it in the KEV catalog, and ENISA does not report it as exploited.
How to protect the router from CVE-2023-32154?
Since the fixed version has not yet been disclosed, the only available mitigation is to disable the RADVD service if it is not needed, or to restrict its access to trusted networks. It is essential to monitor official MikroTik announcements for the release of a fixed stable version.
Which RouterOS commands are needed to mitigate CVE-2023-32154?
Update RouterOS
The only definitive fix is an update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
Does CVE-2023-32154 require authentication?
No, CVE-2023-32154 does not require authentication to be exploited. An attacker on the local network can execute code with root privileges without credentials.
What is the CVSS score for CVE-2023-32154?
The CVSS v3.1 and v4.0 scores have not yet been disclosed. Specific severity is not available in current sources.
Is CVE-2023-32154 in the CISA KEV catalog?
No, CVE-2023-32154 is not present in the CISA KEV catalog. It is not reported as actively exploited according to available data.
Which RouterOS versions fix CVE-2023-32154?
The fixed version for CVE-2023-32154 has not yet been disclosed. Affected versions include 6.49.7 Stable and, according to NVD, all versions prior to 6.48.7.



