This document describes a Denial of Service (DoS) vulnerability found in certain versions of MikroTik RouterOS. The vulnerability is due to insufficient handling of crafted SMB requests. A remote attacker could exploit this issue by sending a specially crafted request to the target server.
# MikroTik RouterOS Denial of Service Vulnerability
## 📌 Description
This document describes a **Denial of Service (DoS) vulnerability** found in certain versions of **MikroTik RouterOS**.
The vulnerability is due to **insufficient handling of crafted SMB requests**. A remote attacker could exploit this issue by sending a specially crafted request to the target server.
> ✅ **Successful exploitation** could result in the **crash or unresponsiveness** of the affected system.
---
## 🎯 Affected Products
| Product | Affected Versions |
|----------------------|-------------------------|
| MikroTik RouterOS | 6.40.5 to 6.44 |
| MikroTik RouterOS | 6.48.1 to 6.49.10 |
---
## 💥 Impact
- **Denial of Service (DoS)**
Remote attackers can crash or disrupt the operation of vulnerable MikroTik RouterOS systems.
---
## 🛡️ Recommended Actions
- 🔄 **Upgrade to the latest patched version** provided by MikroTik.
- 📥 Download the latest version here:
👉 [https://mikrotik.com/download](https://mikrotik.com/download)
---
## 📡 Coverage
| IPS Database | Status |
|----------------------|------------------|
| IPS (Regular DB) | ✅ Covered |
| IPS (Extended DB) | ✅ Covered |
---
## 📅 Version Updates
| Date | Version | Detail |
|------------|-----------|------------------------------|
| 2024-06-03 | 28.799 | Default action: `pass:drop` |
| 2024-05-23 | 27.792 | Initial detection added |
---
## 📝 References
- MikroTik Official Website: [https://mikrotik.com](https://mikrotik.com)
- CVE (if applicable): _Not specified_
---
> ℹ️ Always keep your systems up to date and monitor vendor advisories for future patches or improvements.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view