CRITICAL🇵🇱 Wersja polska

CVE-2017-20149

CVSS 9.8v3.1pub. 2022-10-15upd. 2025-05-14

The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Mikrotik Routeros

    OS
    Mikrotik
    < 6.37.56.38 – 6.38.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2018-14847CRITICAL9.1⚠ KEVPL ✓same product

MikroTik RouterOS — path traversal w interfejsie WinBox (odczyt/zapis plików)

CVE-2018-7445CRITICAL9.8⚠ KEVPL ✓same product

MikroTik RouterOS SMB — buffer overflow przed uwierzytelnieniem (RCE)

CVE-2023-30799CRITICAL9.1PL ✓same product

MikroTik RouterOS — privilege escalation admin do super-admin z możliwością RCE

CVE-2022-34960CRITICAL9.8PL ✓same product

MikroTik RouterOS: path traversal przez symlinki w pakiecie container

CVE-2025-6443HIGH7.2same product

Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote atta...