Improper Authentication in MikroTik RouterOS - #VU24728

 

Improper Authentication in MikroTik RouterOS - #VU24728

Published: January 29, 2020


Vulnerability identifier: #VU24728
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when loading default router configuration for routers with default admin password and Wireless Wire enabled. A remote attacker on the local network can login with admin account and empty password before the default configuration is fully loaded.


Affected software

MikroTik RouterOS

Remediation

Install updates from vendor's website.

MikroTik RouterOS - addressed in versions 6.45.8, 6.46.2

External References

Related Security Bulletins