CVE CVE-2024-54772
Severity MEDIUM · CVSS 3.1 5.4
Weakness CWE-208
Affected versions < 6.49.18, < 7.18
First non-vulnerable version 6.49.18, 7.18 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2025-02-11

What is the CVE-2024-54772 vulnerability?

CVE-2024-54772 is an “Observable Timing Discrepancy” weakness in the Winbox service. The issue arises from a discrepancy in response size between connection attempts made with a valid username and those made with an invalid username. This difference allows an attacker to enumerate valid accounts present on the system.

Which RouterOS versions are vulnerable?

The vulnerable versions are the long-term releases from v6.43.13 to v6.49.13 and the stable releases from v6.43 to v7.17.2. The available corrective version is stable v6.49.18. For 7.x versions, the JSON indicates that versions lower than 7.18 are vulnerable, but it does not specify an exact corrective version for this line, so it is recommended to check for the latest available stable update.

Is my router at risk?

A router is at risk if the Winbox service is active and reachable from untrusted networks. Since the vulnerability exploits response time differences, any host capable of sending Winbox requests to the router can attempt account enumeration. If Winbox is restricted to the internal administration network only, the risk is significantly reduced.

Is the CVE-2024-54772 vulnerability actively exploited?

As of the date of the article, CVE-2024-54772 is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of known active exploitation.

How to protect the router from CVE-2024-54772?

The primary measure is to update RouterOS to version 6.49.18 or higher, which includes the patch for this vulnerability. Alternatively or additionally, you can mitigate the risk by restricting access to the Winbox service exclusively to the administration network, thereby preventing external hosts from sending requests and measuring response time differences.

Which RouterOS commands are needed to mitigate CVE-2024-54772?

Temporary mitigation: winbox service

The defect concerns Winbox, both via IP and via MAC address. Both access methods must be restricted to the administration network.

/ip service print
# Winbox via IP solo dalla rete di gestione (sostituisci con la tua)
/ip service set winbox address=192.168.88.0/24
# Winbox via MAC: spegnilo, o limitalo a un'interface-list di gestione
/tool mac-server mac-winbox set allowed-interface-list=none

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2024-54772?

The CVSS v3.1 score assigned to CVE-2024-54772 is 5.4, with MEDIUM severity. The vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N.

Is authentication required to exploit CVE-2024-54772?

Yes, the CVSS vector indicates PR:L (Privileges Required: Low), which means the attacker must have low privileges or access to the Winbox service to perform account enumeration.

What is the corrective version for 6.x releases?

The specified corrective version for 6.x releases is v6.49.18, which resolves the vulnerability in previous long-term and stable versions.

Is vulnerability CVE-2024-54772 in the CISA KEV catalog?

No, CVE-2024-54772 is not present in the CISA KEV catalog as of the date of the article, indicating that it is not known to be actively exploited.

Does disabling Winbox eliminate the risk of CVE-2024-54772?

Yes, disabling or restricting access to the Winbox service prevents an external attacker from sending the requests necessary to measure response time differences, thereby eliminating the specific attack vector of this vulnerability.

Official sources