New Exploit for MikroTik Router WinBox Vulnerability Gives Full Root Access
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-1156 | Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to stack buffer overflow through the license upgrade interface. Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to stack buffer overflow through the license upgrade interface. This vulnerability could theoretically allow a remote authenticated attacker execute arbitrary code on the system. NVD description · AI analysis pending | 8.8 group max | 7% | PoC |
| — | |
| CVE-2018-14847 | Directory Traversal in MikroTik RouterOS Winbox Interface (Unauthenticated File Read) CVE-2018-14847 is a directory traversal (CWE-22) vulnerability in the Winbox interface of MikroTik RouterOS through version 6.42. An unauthenticated remote attacker can send crafted Winbox requests that traverse directories to read arbitrary files on the device, while authenticated attackers can also write arbitrary files. By reading files an attacker can retrieve sensitive device data such as stored credentials or configuration, and file write capability can support further compromise of the router. Any MikroTik router or device running RouterOS at or below 6.42 with the Winbox interface reachable is affected, which includes large numbers of internet-exposed edge and ISP devices. The flaw is actively exploited: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-12-01), has multiple public PoCs, and compromised MikroTik routers have been used by threats such as Trickbot (as C2 proxies) and the Mēris botnet, with public scans reporting over 300,000 vulnerable devices. Do: Apply MikroTik's updates per vendor instructions, moving RouterOS above version 6.42, prioritizing devices with Winbox reachable from untrusted networks. Until patched, restrict or disable Winbox access from WAN/untrusted interfaces to limit unauthenticated file reads. Given known botnet abuse of this flaw, check devices for signs of compromise and rotate credentials that may have been exposed via file reads. | 9.1 | 96% | KEV PoC ×7 |
| mass≈300,000+ internet-exposed MikroTik devices |
Full article512 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalOct 08, 2018
A known vulnerability in MikroTik routers is potentially far more dangerous than previously thought.
A cybersecurity researcher from Tenable Research has released a new proof-of-concept (PoC) RCE attack for an old directory traversal vulnerability that was found and patched within a day of its discovery in April this year.
The vulnerability, identified as CVE-2018-14847, was initially rated as medium in severity but should now be rated critical because the new hacking technique used against vulnerable MikroTik routers allows attackers to remotely execute code on affected devices and gain a root shell.
The vulnerability impacts Winbox—a management component for administrators to set up their routers using a Web-based interface—and a Windows GUI application for the RouterOS software used by the MikroTik devices.
The vulnerability allows "remote attackers to bypass authentication and read arbitrary files by modifying a request to change one byte related to a Session ID."
New Hack Turned 'Medium' MikroTik Vulnerability Into 'Critical'
However, the new attack method found by Tenable Research exploits the same vulnerability and takes it to one step ahead.
A PoC exploit, called "By the Way," released by Tenable Research Jacob Baines, first uses directory traversal vulnerability to steal administrator login credentials from user database file and the then writes another file on the system to gain root shell access remotely.
In other words, the new exploit could allow unauthorized attackers to hack MikroTik's RouterOS system, deploy malware payloads or bypass router firewall protections.
The technique is yet another security blow against MikroTik routers, which was previously targeted by the VPNFilter malware and used in an extensive cryptojacking campaign uncovered a few months ago.
New MikroTik Router Vulnerabilities
Besides this, Tenable Research also disclosed additional MikroTik RouterOS vulnerabilities, including:
- CVE-2018-1156—A stack buffer overflow flaw that could allow an authenticated remote code execution, allowing attackers to gain full system access and access to any internal system that uses the router.
- CVE-2018-1157—A file upload memory exhaustion flaw that allows an authenticated remote attacker to crash the HTTP server.
- CVE-2018-1159—A www memory corruption flaw that could crash the HTTP server by rapidly authenticating and disconnecting.
- CVE-2018-1158—A recursive parsing stack exhaustion issue that could crash the HTTP server via recursive parsing of JSON.
The vulnerabilities impact Mikrotik RouterOS firmware versions before 6.42.7 and 6.40.9.
Tenable Research reported the issues to MikroTik in May, and the company addressed the vulnerabilities by releasing its RouterOS versions 6.40.9, 6.42.7 and 6.43 in August.
While all the vulnerabilities were patched over a month ago, a recent scan by Tenable Research revealed that 70 percent of routers (which equals to 200,000) are still vulnerable to attack.
The bottom line: If you own a MikroTik router and you have not updated its RouterOS, you should do it right now.
Also, if you are still using default credentials on your router, it is high time to change the default password and keep a unique, long and complex password.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2018/10/router-hacking-exploit.html