CVE-2019-3977 affects MikroTik RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and earlier, stemming from insufficient validation of upgrade package sources during autoupgrade. This allows a remote attacker to trick the router into downgrading to an older version, potentially resetting all system usernames and passwords. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, leading to high integrity impact. While there is no known exploit code in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation, though it is not currently listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.44.5CPE matchmatch criteria | cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:* | ||
<= 6.45.6CPE matchmatch criteria | cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019