CVE-2019-3978
HIGH IN THE WILDMikrotik Routeros < 6.44.5 - Missing Authentication
Title source: ruleDescription
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS responses are cached by the router, potentially resulting in cache poisoning
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.1661
EPSS Percentile
94.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation Intel
InTheWild.io
2021-12-10
Classification
CWE
CWE-306
Status
published
Affected Products (2)
mikrotik/routeros
< 6.44.5
mikrotik/routeros
< 6.45.6
Timeline
Published
Oct 29, 2019
Tracked Since
Feb 18, 2026