CVE-2018-7445

MikroTik RouterOS: Stack-Based Buffer Overflow

As of , CVE-2018-7445 in MikroTik RouterOS is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 8 September 2022
US federal deadline
29 September 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.61Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.12 on 8 September 2022EPSS on the day CISA listed it.
Public exploit
1 Exploit-DB entry
Fix
Vendor advice: www.coresecurity.comLinks below, from CISA's entry.

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system.

CISA's description

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.

The CVE record's description, from mitre

CVE published
19 March 2018
Assigned by
mitre
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. Exploit-DB published an exploit (EDB-ID 44290).
  2. The CVE record was published.
  3. CISA added it to its list of exploited vulnerabilities.
  4. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

RouterOS: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-86060Improper Neutralization of Argument Delimiters in a CommandMikroTik RouterOSPatch nowForensic triage required by CISA0.06
CVE-2026-67279Improper Enforcement of Behavioral WorkflowMikroTik RouterOSPatch nowListed in the last 14 days0.01
CVE-2018-14847Router OS Directory TraversalMikroTik RouterOSPatch this weekMetasploit module; EPSS 0.960.96
CVE-2026-67277Missing Authentication for Critical FunctionMikroTik RouterOSPatch soon0.02

Read further