CVE-2018-7445
KEV PoC ×3massPre-Authentication Stack Buffer Overflow RCE in MikroTik RouterOS SMB
CISA: MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability
CVE-2018-7445 is a stack-based buffer overflow (CWE-119) in the SMB service of MikroTik RouterOS that occurs while processing NetBIOS session request messages. An attacker triggers it simply by sending a crafted NetBIOS session request to the device's SMB service; because the overflow occurs before authentication, no credentials or user interaction are required. Successful exploitation yields unauthenticated remote code execution on the router, giving the attacker a foothold on the device itself and a potential pivot point into the networks it serves. All MikroTik devices on all architectures running RouterOS before 6.41.3 (stable branch) or 6.42rc27 (release-candidate branch) are affected wherever the SMB service is reachable. Exploitation is confirmed: public proof-of-concept code has existed since March 2018 (Core Security advisory, Exploit-DB 44290), EPSS assigns a ~61% 30-day exploitation probability, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-09-08, indicating in-the-wild use (ransomware use unknown).
What to do: Upgrade all MikroTik devices to RouterOS 6.41.3 or later on the stable branch (or 6.42rc27 or later on the release-candidate branch), per the CISA KEV required action. Until patched, disable the SMB service where it is not needed or firewall-restrict SMB ports so only trusted hosts can reach it. Audit RouterOS versions across your fleet, prioritizing internet-facing routers given confirmed in-the-wild exploitation.
| MikroTik RouterOS | All versions prior to 6.41.3 (stable) and prior to 6.42rc27 (release-candidate branch); all architectures, all devices |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.
- Affected
- MikroTik RouterOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- mikrotik
- Products
- routeros
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H