PT-2025-6403 · Mikrotik · Routeros+1
Deauther890
·
Published
2024-11-27
·
Updated
2026-03-10
·
CVE-2024-54772
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
MikroTik RouterOS versions 6.43 through 7.16.1
Description
A discrepancy in response times between connection attempts made with a valid username and those with an invalid username in the Winbox service allows attackers to enumerate valid accounts.
Recommendations
For versions 6.43 through 7.16.1, consider disabling the Winbox service until a patch is available to prevent attackers from enumerating valid accounts. Restrict access to the Winbox service to minimize the risk of exploitation. Avoid using the Winbox service for authentication until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mikrotik Routeros
Routeros