CVE-2018-7445

CRITICAL KEV

MikroTik RouterOS < 6.41.3 - Unauthenticated Remote Code Execution via SMB NetBIOS Session Request

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-7445 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added September 8, 2022. EIP tracks 2 public exploits from researchers including CoreLabs.

AI-analyzed exploit summary This exploit targets CVE-2018-7445, a buffer overflow in Samba, to achieve remote code execution. It uses a combination of ROP and shellcode to bypass protections and spawn a reverse shell.

Description

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.

Exploits (2)

exploitdb WORKING POC
by CoreLabs · pythonremotehardware
https://www.exploit-db.com/exploits/44290

This exploit targets CVE-2018-7445, a buffer overflow in Samba, to achieve remote code execution. It uses a combination of ROP and shellcode to bypass protections and spawn a reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samba 3.5.0 to 4.6.16/4.7.6/4.8.3
No auth needed
Prerequisites: Network access to target · Samba service exposed on port 139
devstral-2 · analyzed Feb 16, 2026 Full analysis →
vulncheck_xdb WORKING POC
remote
https://github.com/BigNerd95/Chimay-Blue

This repository contains functional exploit code for CVE-2018-7445, a buffer overflow vulnerability in MikroTik RouterOS SMB service. The exploit includes both MIPS and x86 payloads, demonstrating remote code execution by leveraging cache flushing techniques and ROP chains.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: MikroTik RouterOS (versions up to 6.41.2)
No auth needed
Prerequisites: Network access to the SMB service (port 139) · Vulnerable MikroTik RouterOS version
devstral-2 · analyzed Feb 25, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103427
Exploit, Mailing List, Third Party Advisory, VDB Entry mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Mar/38
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44290/

Scores

CVSS v3 9.8
EPSS 0.6102
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-09-08
VulnCheck KEV 2020-12-01
InTheWild.io 2018-05-12
ENISA EUVD EUVD-2018-19176
CWE
CWE-119
Status published
Products (2)
mikrotik/routeros 6.42 rc11 (12 CPE variants)
mikrotik/routeros < 6.41.3
Published Mar 19, 2018
KEV Added Sep 08, 2022
Tracked Since Feb 18, 2026