#VU22426 Incorrect permission assignment for critical resource in MikroTik RouterOS - CVE-2019-3978
Published: October 30, 2019 / Updated: June 17, 2021
MikroTik RouterOS
MikroTik
Description
The vulnerability allows a remote attacker to perform DNS cache poisoning attacks.
The vulnerability exists due to RouterOS allows a remote attacker to initiate DNS queries via port 8291/TCP. A remote attacker can force the router to send DNS requests to an attacker-contorted server and poison router's DNS cache.