ZDI-CAN-19797: ZDI-23-710: (0Day) (Pwn2Own) Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability
Published May 17, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Mikrotik RouterOS
Event History
May 17, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Feb 26, 2025
Advisory Published
via ZDI·08:02 AM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19797?
The severity of ZDI-CAN-19797 is critical due to its potential for arbitrary code execution by network-adjacent attackers.
2
How do I fix ZDI-CAN-19797?
To fix ZDI-CAN-19797, update your Mikrotik RouterOS to the latest version provided by the vendor.
3
Who is affected by ZDI-CAN-19797?
ZDI-CAN-19797 affects all installations of Mikrotik RouterOS that are accessible on the network.
4
Is authentication required to exploit ZDI-CAN-19797?
No, authentication is not required to exploit ZDI-CAN-19797, making it a particularly dangerous vulnerability.
5
What types of attacks can ZDI-CAN-19797 enable?
ZDI-CAN-19797 can enable attackers to execute arbitrary code remotely on the affected Mikrotik RouterOS installations.