MikroTik RouterOS
What happened
The upgrade can be downloaded from the MikroTik website. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
View CVE Details Affected Products MikroTik RouterOS Vendor: MikroTik Product Version: MikroTik RouterOS: < 7.24 Product Status: known_affected Remediations Vendor fix MikroTik recommends users update RouterOS to version 7.23 or later. Legal Notice and Terms of Use This product is provided subject to this Notification ( https://www.cisa.gov/notification ) and this Privacy & Use policy ( https://www.cisa.gov/privacy-policy ).
Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
Sources & evidence
- CISA Advisories Primary / official
MikroTik RouterOS ↗
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06