QID 730736
Date Published: 2023-02-23
QID 730736: MikroTik RouterOS Out-of-bounds Write Vulnerability
MikroTik RouterOS is the operating system of MikroTik RouterBOARD hardware.
Affected Versions:
MikroTik RouterOS 6.46.8
MikroTik RouterOS 6.47.9
MikroTik RouterOS 6.47.10
QID Detection Logic(Unauthenticated):
It uses page source h1 tag to detect vulnerable version of MikroTik RouterOS.
An attacker can trigger a heap-based buffer overflow that leads to remote code execution.
Solution
Customers are advised to upgrade to latest versions and can be downloaded from MikroTik RouterOS Downloads.
Vendor References
CVEs related to QID 730736
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-41987 |
|