CVE-2017-17537
HIGHMikroTik RouterBOARD 6.39.2 and 6.40.5 - Unauthenticated Denial of Service via TCP Port 53
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-17537. PoCs published by Mr Bruce.
AI-analyzed exploit summary This exploit sends a malformed HTTP POST request with an oversized 'username' parameter to trigger a buffer overflow vulnerability. It targets a web server's login endpoint, likely causing a denial-of-service or potential remote code execution if the overflow is exploitable.
Description
MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and sending data that begins with many '\0' characters, possibly related to DNS.
Exploits (1)
This exploit sends a malformed HTTP POST request with an oversized 'username' parameter to trigger a buffer overflow vulnerability. It targets a web server's login endpoint, likely causing a denial-of-service or potential remote code execution if the overflow is exploitable.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H