CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2018-7445

CVSS 9.8v3.1pub. 2018-03-19upd. 2025-11-07

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Mikrotik Routeros

    OS
    Mikrotik
    6.42< 6.41.3

CISA KEV — detailsi

Vendori
MikroTik
Producti
RouterOS
Added to KEVi
September 8, 2022
Remediation deadline (US Federal)i
September 29, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 29 września 2022
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2018-14847CRITICAL9.1⚠ KEVPL ✓same product

MikroTik RouterOS — path traversal w interfejsie WinBox (odczyt/zapis plików)

CVE-2023-30799CRITICAL9.1PL ✓same product

MikroTik RouterOS — privilege escalation admin do super-admin z możliwością RCE

CVE-2017-20149CRITICAL9.8PL ✓same product

MikroTik RouterOS — RCE przez uszkodzenie pamięci w serwerze WWW (Chimay-Red)

CVE-2022-34960CRITICAL9.8PL ✓same product

MikroTik RouterOS: path traversal przez symlinki w pakiecie container

CVE-2025-6443HIGH7.2same product

Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote atta...