CVE-2024-2169

HIGH

MikroTik RouterOS-TFTP < 7.13.2 - Unauthenticated Denial of Service via UDP Network Loop

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-2169. PoCs published by renancesarr.

AI-analyzed exploit summary The repository contains a scanner tool for detecting potential vulnerabilities related to CVE-2024-2169 by sending crafted packets to NTP, DNS, and SNMP services. It includes a command-line interface for configuring scans but does not demonstrate exploitation.

Description

Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.

Exploits (1)

nomisec SCANNER
by renancesarr · poc
https://github.com/renancesarr/G3-Loop-DoS

The repository contains a scanner tool for detecting potential vulnerabilities related to CVE-2024-2169 by sending crafted packets to NTP, DNS, and SNMP services. It includes a command-line interface for configuring scans but does not demonstrate exploitation.

Classification
Scanner 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Theoretical
Target: NTP, DNS, and SNMP services (specific versions not specified)
No auth needed
Prerequisites: Network access to target services · Open ports for NTP (123), DNS (53), or SNMP (161)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, US Government Resource
https://kb.cert.org/vuls/id/417980
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/417980

Scores

CVSS v3 7.5
EPSS 0.0540
EPSS Percentile 91.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

Status published
Products (3)
dproxy-nexgen/dproxy-nexgen 0.1 - 0.5
Microsoft/WDS
MikroTik/RouterOS-TFTP < 7.13.2
Published Mar 19, 2024
Tracked Since Feb 18, 2026