Record summary

CVE-2023-30799 has a selected CVSS score of 9.1 (critical); EIP currently links 1 repository PoC.

Description

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 18, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 24, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List, VulnCheckBefore 6.49.7affected
Through 6.48.6affected

Proofs of concept

1

Repository PoCs

GitHubalzeer711/MikroTik-RouterOS-6.49.18-Exploit-KitRepository PoCby alzeer711Stars: 1Not analyzed3 files

12.4 KiB

GitHub

PoC details

References

3