PT-2025-23197 · Mikrotik · Mikrotik Routeros

Published

2024-11-21

·

Updated

2025-06-30

·

CVE-2024-54952

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MikroTik RouterOS version 6.40.5
Description The SMB service in MikroTik RouterOS contains a memory corruption issue. Remote, unauthenticated attackers can exploit this by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Service (DoS), rendering the SMB service unavailable.
Recommendations For MikroTik RouterOS version 6.40.5, consider disabling the SMB service until a patch is available to prevent Remote Denial of Service (DoS) attacks.

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-06641
CVE-2024-54952

Affected Products

Mikrotik Routeros