Skip to main content

MikroTik RouterOS SMB Vulnerability

A vulnerability in MikroTik's RouterOS software Server Message Block (SMB) service may allow a remote, unauthenticated attacker to execute arbitrary code.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability in MikroTik's RouterOS software Server Message Block (SMB) service may allow a remote, unauthenticated attacker to execute arbitrary code.

Threat details

CVE-2018-7445 is a buffer overflow vulnerability that occurs when processing netBIOS session requests over SMB. Under certain conditions the first byte of the source buffer is not read, but is still passed to the destination buffer. This means any further data is not checked to ensure it will fit within the destination buffer.

Exploitation of this vulnerability requires detailed knowledge of the targeted device and the attack process must be tailored to each MikroTik product.

MikroTik are a small Latvian network hardware and software vendor. Their products are used worldwide in primarily commercial or business areas.

Confirmed Vulnerable Software Versions (List may not be comprehensive or current):

  • MikroTik RouterOS 2.9.40
  • MikroTik RouterOS 2.9.41
  • MikroTik RouterOS 2.9.42
  • MikroTik RouterOS 2.9.43
  • MikroTik RouterOS 2.9.44
  • MikroTik RouterOS 2.9.45
  • MikroTik RouterOS 2.9.46
  • MikroTik RouterOS 2.9.47
  • MikroTik RouterOS 2.9.48
  • MikroTik RouterOS 2.9.49
  • MikroTik RouterOS 2.9.50
  • MikroTik RouterOS 2.9.51
  • MikroTik RouterOS 3.0
  • MikroTik RouterOS 3.07
  • MikroTik RouterOS 3.08
  • MikroTik RouterOS 3.09
  • MikroTik RouterOS 3.10
  • MikroTik RouterOS 3.11
  • MikroTik RouterOS 3.12
  • MikroTik RouterOS 3.13
  • MikroTik RouterOS 3.2
  • MikroTik RouterOS 4.0
  • MikroTik RouterOS 5.0
  • MikroTik RouterOS 5.15
  • MikroTik RouterOS 5.25
  • MikroTik RouterOS 5.26
  • MikroTik RouterOS 6.2
  • MikroTik RouterOS 6.3

Threat updates

Date Update
24 Apr 2018

New evidence of criminal gangs in Brazil targeting organisations throughout Western Europe has emerged. The attackers are exploiting the MikroTik SMB vulnerability to gain initial access to networks before using affected routers to further infect other devices on the network.


Remediation steps

Type Step
  • MikroTik have confirmed that the vulnerability is not present in version 6.41.3 of RouterOS, found here. Administrators should apply this update immediately.
  • SMB should be disabled unless explicitly required.


CVE Vulnerabilities

Last edited: 17 February 2020 12:49 pm