CVE-2018-1159 describes a memory corruption vulnerability affecting Mikrotik RouterOS versions prior to 6.42.7 and 6.40.9. An authenticated remote attacker can exploit this flaw to crash the HTTP server by repeatedly authenticating and disconnecting. This vulnerability is rated Medium severity with a CVSS score of 6.5, indicating a network-based attack with low attack complexity and requiring low privileges, leading to high availability impact. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.40.9CPE matchmatch criteria | cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:* | ||
< 6.42.7CPE matchmatch criteria | cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Mikrotik RouterOS Multiple Authenticated Vulnerabilities
Aug 22, 2018[R1] Mikrotik RouterOS Multiple Authenticated Vulnerabilities
Aug 22, 2018Mikrotik RouterOS Multiple Authenticated Vulnerabilities
Aug 22, 2018[R1] Mikrotik RouterOS Multiple Authenticated Vulnerabilities
Aug 22, 2018