Description
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- MikroTik / RouterOS6.49.10 – 6.49.10
- MikroTik / RouterOS6.49.9 – 6.49.9
- MikroTik / RouterOS6.48.8 – 6.48.8
References
- VENDOR_ADVISORYhttps://vulncheck.com/advisories/mikrotik-jsproxy-dos
Updated 7m ago · 8 sources