CVE-2018-7445

CRITICAL KEV

Mikrotik Routeros < 6.41.3 - Memory Corruption

Title source: rule

Description

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.

Exploits (2)

exploitdb WORKING POC
by CoreLabs · pythonremotehardware
https://www.exploit-db.com/exploits/44290
vulncheck_xdb WORKING POC
remote
https://github.com/BigNerd95/Chimay-Blue

Scores

CVSS v3 9.8
EPSS 0.8756
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-09-08
VulnCheck KEV 2020-12-01
InTheWild.io 2018-05-12
ENISA EUVD EUVD-2018-19176
CWE
CWE-119
Status published
Products (2)
mikrotik/routeros 6.42 rc11 (12 CPE variants)
mikrotik/routeros < 6.41.3
Published Mar 19, 2018
KEV Added Sep 08, 2022
Tracked Since Feb 18, 2026