HomeSecurityVulnerability exploited for DoS attacks on MikroTik routers

Vulnerability exploited for DoS attacks on MikroTik routers

MikroTikMikroTik has revealed that there is a vulnerability in MikroTik routers, which could allow hackers to perform remote attacks, specifically a denial-of-service attack, on devices running RouterOS.

“RouterOS had several issues related to IPv6, which have been fixed,” the company in a blog post.

The first issue had to do with the device rebooting. The reboot was triggered by the watchdog timer, since the device had become overloaded and stopped responding.

The company has issued security updates for RouterOS (CVE-2018-19299), but some experts say there are still some devices that are vulnerable.

The vulnerability CVE-2018-19299 affects MikroTik devices with IPv6 packets that have not received the update . The vulnerability can be exploited by hackers to cause RAM problems.

"After addressing the first issue, another RAM issue arose, as the IPv6 cache size was larger than the available RAM. And this issue was fixed by introducing automatic IPv6 cache calculation based on available memory," the company said.

MikroTik addressed the issues in RouterOSv6.44.2, RouterOS v6.45beta23, and RouterOSv6.43.14.

However, according to experts, the fixes do not work for all devices, but only for those with more than 64MB of RAM.

The vulnerability has been known since April 2018 and was known to the company itself but had not considered it a security vulnerability. However, in March, evidence was revealed that proved the existence of the vulnerability and its exploitation by hackers.

The vulnerability, CVE-2018-19299, affects almost all MikroTik devices. According to Bleeping Computer, MikroTik has released more than 20 versions of RouterOS since it learned about the vulnerability. This is because, first, it did not realize that it was a security flaw, and second, because it is at the kernel level, so it is not easy to fix.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS