PT-2023-4988 · Mikrotik · Routeros+1

·

CVE-2023-30800

·

Published

2023-04-18

·

Updated

2025-11-21

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MikroTik RouterOS versions prior to 6.49.10
Description The web server used by MikroTik RouterOS is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted.
Recommendations For versions prior to 6.49.10, update to RouterOS 6.49.10 stable or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05527
CVE-2023-30800

Affected Products

Mikrotik Routeros
Routeros