Security researchers have discovered a vulnerability in the operating system of MikroTik routers.

Specifically, a buffer overflow is observed in MikroTik RouterOS SMB when processing requests in the NetBIOS protocol. Server Message Block is a protocol for sharing files, printers, serial ports, and other communications between different computers.
MikroTik provides hardware and software for Internet connectivity in most countries around the world. RouterOS is MikroTik's standalone operating system based on the Linux v3.3.5 kernel and serves major companies such as Vodafone, Ericsson and NASA supported by over 500 distributors and resellers in 145 countries.
According to the researchers, remote attackers with access to the service could exploit the vulnerability and gain access to the system. All architectures and all devices running RouterOS prior to versions 6.41.3 / 6.42rc27 – 6.41.2 were vulnerable
The timeline published by Core Security showed that MikroTik confirmed that it had patched the vulnerability on March 12, 2018, and released a new version of RouterOS (6.41.3). It also suggested disabling the SMB service in cases where installing the new updated version is not possible.
The vulnerability was discovered and researched by Juan Caillava and Maximiliano Vidal from Core Security Consulting Services and published by Leandro Cuozzo from the Core Advisories team.
