CVE-2021-41987 is a heap-based buffer overflow vulnerability in the SCEP Server component of Mikrotik RouterOS versions 6.46.8, 6.47.9, and 6.47.10, allowing for remote code execution. This high-severity flaw (CVSS 8.1) requires an attacker to know the scep_server_name value, but otherwise has low attack complexity and no user interaction. While its EPSS and FAUCET scores indicate significant potential risk, there is currently no evidence of active exploitation, public exploit code, or community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.46.8CPE matchmatch criteria | cpe:2.3:o:mikrotik:routeros:6.46.8:*:*:*:*:*:*:* | ||
6.47.9CPE matchmatch criteria | cpe:2.3:o:mikrotik:routeros:6.47.9:*:*:*:*:*:*:* | ||
6.47.10CPE matchmatch criteria | cpe:2.3:o:mikrotik:routeros:6.47.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.