First published: Mon Apr 16 2018(Updated: )
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on port 21 that begins with many '\0' characters, preventing the affected router from accepting new FTP connections. The router will reboot after 10 minutes, logging a "router was rebooted without proper shutdown" message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mikrotik Router Firmware | =6.41.4 | |
Mikrotik Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10070 is classified as a denial of service vulnerability which can affect the functionality of MikroTik routers.
To mitigate CVE-2018-10070, update your MikroTik router firmware to a version later than 6.41.4.
CVE-2018-10070 allows an unauthenticated remote attacker to perform a denial of service attack by sending crafted FTP requests.
CVE-2018-10070 specifically affects MikroTik Router Firmware version 6.41.4.
Exploiting CVE-2018-10070 could lead to the router exhausting CPU and RAM resources, resulting in denial of service.