Skip to content
Topic

Denial of Service

Vulnerabilities that block or restart the router or one of its services: all dojo articles on this topic.

Illustrazione per CVE-2020-22845
Security High · 7.5
CVE-2020-22845

Buffer overflow in the FTP service of RouterOS 6.47

CVE-2020-22845 is a buffer overflow in the FTP service of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service via malicious FTP requests. The vulnerability has HIGH severity (CVSS 7.5) and specifically affects version 6.47. To mitigate the risk, you must update to a later version or disable the FTP service if not strictly necessary.

2 min read
Illustrazione per Buffer overflow nel server SMB di RouterOSSecurity
CVE-2020-22844

Buffer overflow in the SMB server of RouterOS

CVE-2020-22844 is a buffer overflow in the SMB server of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service through malicious SMB requests. The vulnerability specifically affects version 6.47 and is not known to be actively exploited. To mitigate the risk, you must update the firmware or disable the SMB service if it is not in use.

High · 7.5
Illustrazione per CVE-2019-16160Security
CVE-2019-16160

Integer underflow in the RouterOS SMB server

CVE-2019-16160 is an integer underflow in the RouterOS SMB server that allows an unauthenticated remote attacker to crash the service. RouterOS versions prior to 6.45.5 are affected. To mitigate the risk, upgrade to a later version or disable the SMB service if not required.

High · 7.5
Illustrazione per CVE-2020-11881Security
CVE-2020-11881

SMB server crash in RouterOS

CVE-2020-11881 is an array index validation error in the RouterOS SMB server that allows a remote unauthenticated attacker to cause a service crash. It affects versions 6.41.3 through 6.46.5 and 7.x versions up to 7.0 Beta5. Immediate mitigation is to disable the SMB server if not strictly necessary, as the stable fixed version is not specified in the available data.

High · 7.5
Illustrazione per CVE-2020-10364Security
CVE-2020-10364

Denial of Service in the SSH daemon

CVE-2020-10364 is a high-severity vulnerability that allows a remote attacker to cause a denial of service (DoS) on the router, generating excessive CPU activity and potential reboots. It affects systems with the SSH daemon active and reachable from untrusted networks. The primary mitigation is to restrict access to the SSH service to the administration network only or disable it if not required.

High · 7.5
Illustrazione per CVE-2018-5951Security
CVE-2018-5951

Reboot risk from IPv6 packet on RouterOS

CVE-2018-5951 is an availability vulnerability that allows a remote attacker to cause an immediate reboot of a MikroTik RouterOS router. The attack exploits the sending of a specific IPv6 packet with IP protocol 97 (EoIPv6). Since the description states that all RouterOS versions supporting EoIPv6 are vulnerable, it is crucial to verify if this service is active and reachable from untrusted networks.

High · 7.5
Illustrazione per Denial of Service nel servizio SMB di RouterOS x86Security
CVE-2024-27686

Denial of Service in the SMB service of RouterOS x86

CVE-2024-27686 allows a remote attacker to crash the device by sending malicious data packets to the SMB service on TCP port 445. This vulnerability affects RouterOS versions 6.40.5 through 6.49.10 for the x86 architecture. To mitigate the risk, you must disable the SMB service or upgrade to a 7.x version, as the fix is only available in the 7 series.

High · 7.5
Illustrazione per CVE-2019-13955Security
CVE-2019-13955

Stack exhaustion in RouterOS WebFig

CVE-2019-13955 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server by sending malicious HTTP requests. It affects RouterOS versions prior to 6.44.5 on the long-term release branch. To mitigate the risk, upgrade to a later version or disable the WebFig service if not required.

Illustrazione per CVE-2019-13954Security
CVE-2019-13954

Memory exhaustion in the RouterOS HTTP server

CVE-2019-13954 is a vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server by sending malicious HTTP requests, potentially causing a system reboot. It affects RouterOS versions prior to 6.44.5. To protect yourself, you must update to a later version or disable the web service if not in use.

Illustrazione per CVE-2019-13074Security
CVE-2019-13074

Memory exhaustion in the RouterOS FTP daemon

CVE-2019-13074 is a vulnerability in the RouterOS FTP daemon that allows a remote attacker to exhaust available memory, causing the device to reboot. It affects versions up to and including 6.44.3. To mitigate the risk, disable the FTP service or upgrade to a later version, if available.

Illustrazione per CVE-2018-1159Security
CVE-2018-1159

Memory vulnerability in the RouterOS HTTP server

CVE-2018-1159 is a memory corruption vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server. Versions prior to 6.40.9 and 6.42.7 are affected. To protect yourself, you must upgrade to a later version or restrict access to the web management service.

Illustrazione per CVE-2018-1158Security
CVE-2018-1158

Stack exhaustion in the RouterOS HTTP server

CVE-2018-1158 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server through recursive JSON parsing. It affects versions prior to 6.40.9 and 6.42.7. To mitigate the risk, upgrade to a later version or restrict access to the web management service to the administration network only.

Illustrazione per CVE-2018-1157Security
CVE-2018-1157

Memory exhaustion in the RouterOS HTTP server

CVE-2018-1157 is a vulnerability that allows an authenticated attacker to crash the HTTP server and, in some cases, reboot the system. It affects RouterOS versions prior to 6.40.9 and 6.42.7. To protect yourself, you must update to a later version or disable the web service if not in use.