CVE-2021-36614: Null Pointer Dereference
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-36614?
CVE-2021-36614 is a memory corruption vulnerability in the tr069-client process of Mikrotik RouterOs before stable version 6.48.2, which can be exploited by an authenticated remote attacker to cause a Denial of Service (NULL pointer dereference).
How does CVE-2021-36614 affect MikroTik RouterOS?
CVE-2021-36614 affects MikroTik RouterOS versions before 6.48.2, making them vulnerable to a memory corruption issue in the tr069-client process.
What is the severity of CVE-2021-36614?
The severity of CVE-2021-36614 is medium with a severity score of 6.5.
How can an attacker exploit CVE-2021-36614?
An authenticated remote attacker can exploit CVE-2021-36614 by triggering a memory corruption vulnerability in the tr069-client process, leading to a Denial of Service (NULL pointer dereference).
How can I mitigate the vulnerability CVE-2021-36614 on MikroTik RouterOS?
To mitigate CVE-2021-36614, it is recommended to update MikroTik RouterOS to version 6.48.2 or later, which includes a fix for the memory corruption vulnerability in the tr069-client process.