Junglewise Threat Intelligence

CVE-2018-7445: MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

CVE-2018-7445 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-09-08

Technologies: MikroTik RouterOS. Vendors: MikroTik.

Executive brief

A stack-based buffer overflow vulnerability exists in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Unauthenticated remote attackers can exploit this to execute arbitrary code on the device.

Affected products

  • MikroTik RouterOS before 6.41.3, before 6.42rc27

Timeline

  • 2018-03-12: disclosed: Full Disclosure mailing list post
  • 2018-04-24: other: Initial NIST analysis
  • 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-09-29: other: CISA required action due date

Related threats