ZeroHour

CVE-2018-7445

KEV PoC ×3mass

Pre-Authentication Stack Buffer Overflow RCE in MikroTik RouterOS SMB

CISA: MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
61%p99
Published
()
KEV added
AI analysis

CVE-2018-7445 is a stack-based buffer overflow (CWE-119) in the SMB service of MikroTik RouterOS that occurs while processing NetBIOS session request messages. An attacker triggers it simply by sending a crafted NetBIOS session request to the device's SMB service; because the overflow occurs before authentication, no credentials or user interaction are required. Successful exploitation yields unauthenticated remote code execution on the router, giving the attacker a foothold on the device itself and a potential pivot point into the networks it serves. All MikroTik devices on all architectures running RouterOS before 6.41.3 (stable branch) or 6.42rc27 (release-candidate branch) are affected wherever the SMB service is reachable. Exploitation is confirmed: public proof-of-concept code has existed since March 2018 (Core Security advisory, Exploit-DB 44290), EPSS assigns a ~61% 30-day exploitation probability, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-09-08, indicating in-the-wild use (ransomware use unknown).

What to do: Upgrade all MikroTik devices to RouterOS 6.41.3 or later on the stable branch (or 6.42rc27 or later on the release-candidate branch), per the CISA KEV required action. Until patched, disable the SMB service where it is not needed or firewall-restrict SMB ports so only trusted hosts can reach it. Audit RouterOS versions across your fleet, prioritizing internet-facing routers given confirmed in-the-wild exploitation.

Affected
MikroTik RouterOSAll versions prior to 6.41.3 (stable) and prior to 6.42rc27 (release-candidate branch); all architectures, all devices
Estimated exposure
mass≈300,000+ internet-exposed MikroTik devices (2018 public scans and reporting counted over 300,000 vulnerable MikroTik devices) — Public internet scans and 2018 security reporting identified more than 300,000 MikroTik devices remotely exposed and vulnerable to pre-authentication flaws, and with the RouterOS installed base in the millions, the SMB-reachable population…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.

CISA Known Exploited Vulnerability
Affected
MikroTik RouterOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
mikrotik
Products
routeros
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news