CVE-2018-10070: High severity mikrotik router firmware vulnerability
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on port 21 that begins with many '\0' characters, preventing the affected router from accepting new FTP connections. The router will reboot after 10 minutes, logging a "router was rebooted without proper shutdown" message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10070?
CVE-2018-10070 is classified as a denial of service vulnerability which can affect the functionality of MikroTik routers.
How do I fix CVE-2018-10070?
To mitigate CVE-2018-10070, update your MikroTik router firmware to a version later than 6.41.4.
What type of attack is associated with CVE-2018-10070?
CVE-2018-10070 allows an unauthenticated remote attacker to perform a denial of service attack by sending crafted FTP requests.
Which MikroTik firmware version is affected by CVE-2018-10070?
CVE-2018-10070 specifically affects MikroTik Router Firmware version 6.41.4.
What could be the impact of exploiting CVE-2018-10070?
Exploiting CVE-2018-10070 could lead to the router exhausting CPU and RAM resources, resulting in denial of service.