CVE Tools

CVE-2018-7445

Exploited in the wild. In CISA KEV since 2022‑09‑08. A vendor fix is available.

Published Updated Sources: CVE.org, NVD, BDU

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check whether your MikroTik RouterOS device is running a version earlier than 6.41.3 and whether the SMB/NetBIOS (SMB service) is enabled.
  2. Confirm the SMB service is reachable from the network (for example, exposed to the internet or reachable from untrusted networks).
  3. Upgrade MikroTik RouterOS to 6.41.3 or later (or the vendor’s newer fixed release) as the fix.
  4. If you cannot upgrade right away, restrict access to the SMB service so it is not reachable from untrusted networks, then upgrade as soon as possible.

What it is

From the CVE record

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.

In plain language

Written by AI from the record

CVE-2018-7445 is a critical, unauthenticated network bug in MikroTik RouterOS’ SMB/NetBIOS handling that can let outsiders take over your device if the SMB service is reachable; small businesses should act immediately if you run this on the internet or an internal network that attackers could reach.

CVE-2018-7445 is an unauthenticated remote code execution buffer overflow in MikroTik RouterOS’ SMB service when processing NetBIOS session request messages; an attacker can send crafted packets over the network to trigger code execution before authentication.

If you're affected

  • Full router takeover
  • Service disruption
  • Malware installation
  • Network-wide compromise

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS99th
Public exploit
CISA KEV
CISA KEV

Listed as exploited in the wild since 2022-09-08.

US federal agencies must remediate by 2022-09-29.

Apply updates per vendor instructions.
Public exploits

3 sources with a proof of concept or module.

Exploit links, PoCs and Metasploit modules after sign-in
EPSS

61% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

The patch came 119 days before any public exploit.

  1. Analysis publishedMikroTik's Newest Router Bugs Were Found by an AI Model. Its Last Two KEV Listings Fueled the Mēris Botnet.
  2. OpenVAS check added
  3. Public exploit / PoCsource: exploit-db
  4. Patch availablerecord updated
  5. Added to CISA KEV
  6. Publishedweakness classified, att&ck mapped

Affected products

And 2 more affected products. See all after sign-in

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Scored 9.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for RouterOS, not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store