Skip to main content
All vulnerabilities
CVE-2018-7445

MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

MikroTikRouterOS

Added to KEV catalog
8 September 2022
Federal remediation due date
29 September 2022
Weakness classification (CWE)
CWE-119

CISA Description

In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.

Required action

Apply updates per vendor instructions.

Notes

https://www.coresecurity.com/core-labs/advisories/mikrotik-routeros-smb-buffer-overflow#vendor_update, https://mikrotik.com/download; https://nvd.nist.gov/vuln/detail/CVE-2018-7445

Confirm Your Exposure

Is this vulnerability present in your environment?

CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.

Explore VAPT Services