PT-2023-4988 · Mikrotik · Routeros+1

Jacob Baines

·

Publicado

2023-04-18

·

Atualizado

2025-11-21

·

CVE-2023-30800

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MikroTik RouterOS versions prior to 6.49.10
Description The web server used by MikroTik RouterOS is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted.
Recommendations For versions prior to 6.49.10, update to RouterOS 6.49.10 stable or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.

Exploit

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05527
CVE-2023-30800

Produtos afetados

Mikrotik Routeros
Routeros