LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-7445: MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 29, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-7445 to its Known Exploited Vulnerabilities catalog on Sep 8, 2022, with a federal patch deadline of Sep 29, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code…

CVE-2018-7445 is a stack-based buffer overflow in MikroTik RouterOS that can be triggered when the device processes NetBIOS session request messages. Remote attackers who can reach the affected service may achieve code execution on the system. For teams running MikroTik gear as edge routers, VPN endpoints, or internal gateways, this matters because successful exploitation can give an attacker control of a network chokepoint.

Public detail is limited to the CISA description and the CWE-119 classification; confirm exact affected builds, fixed releases, and service defaults against the vendor advisory before acting.

How it works

The weakness is CWE-119: improper restriction of operations within the bounds of a memory buffer. In this case a stack-based buffer overflow occurs while RouterOS handles NetBIOS session request messages. An attacker who can send crafted traffic to the listening service can overflow a stack buffer. With sufficient control of the overflow, that can lead to arbitrary code execution in the context of the vulnerable process.

No further exploit mechanics, payload formats, or privilege levels are provided in the available facts. Treat any public proof-of-concept claims with caution and validate them only against official vendor or trusted researcher write-ups. The practical takeaway for defenders is that network-reachable NetBIOS session handling on RouterOS is the attack surface; if that service is exposed, remote code execution is the stated outcome.

Am I affected? How to find it in your systems

MikroTik RouterOS is commonly deployed on MikroTik hardware appliances and on x86 or cloud instances used as routers, firewalls, wireless controllers, or VPN concentrators. Inventory every device running RouterOS, including lab, backup, and out-of-band management units.

How to remediate

Patch first. Apply the RouterOS updates published by MikroTik that address CVE-2018-7445, following the vendor’s installation and reboot guidance. CISA’s required action is to apply updates per vendor instructions; schedule the work in a maintenance window and verify the new version string after reboot.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface and increase detection.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities on network devices frequently precede lateral movement and data theft, even when ransomware use is not documented for this specific CVE. If you have evidence of exploitation or cannot rule it out, treat the device as compromised: isolate it, preserve volatile evidence, rotate credentials and keys that traversed the device, and begin incident-response scoping of adjacent systems. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials tied to your domain already appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMikroTik · RouterOS
WeaknessCWE-119
Added to CISA KEVSep 8, 2022
Federal patch deadlineSep 29, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities