CVE-2018-7445
Exploited in the wild. In CISA KEV since 2022‑09‑08. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check whether your MikroTik RouterOS device is running a version earlier than 6.41.3 and whether the SMB/NetBIOS (SMB service) is enabled.
- Confirm the SMB service is reachable from the network (for example, exposed to the internet or reachable from untrusted networks).
- Upgrade MikroTik RouterOS to 6.41.3 or later (or the vendor’s newer fixed release) as the fix.
- If you cannot upgrade right away, restrict access to the SMB service so it is not reachable from untrusted networks, then upgrade as soon as possible.
What it is
From the CVE record
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.
In plain language
Written by AI from the recordCVE-2018-7445 is a critical, unauthenticated network bug in MikroTik RouterOS’ SMB/NetBIOS handling that can let outsiders take over your device if the SMB service is reachable; small businesses should act immediately if you run this on the internet or an internal network that attackers could reach.
CVE-2018-7445 is an unauthenticated remote code execution buffer overflow in MikroTik RouterOS’ SMB service when processing NetBIOS session request messages; an attacker can send crafted packets over the network to trigger code execution before authentication.
If you're affected
- Full router takeover
- Service disruption
- Malware installation
- Network-wide compromise
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2022-09-08.
US federal agencies must remediate by 2022-09-29.
Apply updates per vendor instructions.
- Public exploits
3 sources with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
61% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
The patch came 119 days before any public exploit.
- Analysis publishedMikroTik's Newest Router Bugs Were Found by an AI Model. Its Last Two KEV Listings Fueled the Mēris Botnet.
- OpenVAS check added
- Public exploit / PoCsource: exploit-db
- Patch availablerecord updated
- Added to CISA KEV
- Publishedweakness classified, att&ck mapped
Affected products
And 2 more affected products. See all after sign-in
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Scored 9.8 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
- Initial AccessT1190Exploit Public-Facing Applicationhigh confidence
- Privilege EscalationT1068Exploitation for Privilege Escalationhigh confidence
Sources
References in the record
- seclists.org/fulldisclosure/2018/Mar/38
- securityfocus.com/bid/103427
- coresecurity.com/advisories/mikrotik-routeros-smb-buffer-overflow
And 4 more references. See all after sign-in
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for RouterOS, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI