PT-2023-4988 · Mikrotik · Routeros+1
Jacob Baines
·
Publicado
2023-04-18
·
Atualizado
2025-11-21
·
CVE-2023-30800
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
MikroTik RouterOS versions prior to 6.49.10
Description
The web server used by MikroTik RouterOS is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted.
Recommendations
For versions prior to 6.49.10, update to RouterOS 6.49.10 stable or later to resolve the issue.
As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.
Exploit
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mikrotik Routeros
Routeros