CVE-2018-10070
HIGHMikroTik Router Firmware 6.41.4 - Unauthenticated Denial of Service via Malformed FTP Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-10070. PoCs published by FarazPajohan.
AI-analyzed exploit summary This exploit demonstrates a denial-of-service (DoS) vulnerability in MikroTik RouterOS by sending crafted FTP requests with multiple null characters, exhausting CPU and RAM resources. The router crashes and reboots after 10 minutes.
Description
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on port 21 that begins with many '\0' characters, preventing the affected router from accepting new FTP connections. The router will reboot after 10 minutes, logging a "router was rebooted without proper shutdown" message.
Exploits (1)
This exploit demonstrates a denial-of-service (DoS) vulnerability in MikroTik RouterOS by sending crafted FTP requests with multiple null characters, exhausting CPU and RAM resources. The router crashes and reboots after 10 minutes.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H