CVE-2024-27686
7.5MikroTik · RouterOS
A denial of service vulnerability in MikroTik RouterOS allows remote attackers to crash affected devices via crafted SMB packets.
Executive summary
An unauthenticated remote denial of service vulnerability in MikroTik RouterOS allows attackers to crash vulnerable devices via crafted packets sent to the SMB service.
Vulnerability
This is a denial of service vulnerability triggered by sending crafted packet data to the SMB service on TCP port 445, requiring no privileges and no user interaction by an unauthenticated attacker.
Business impact
A successful exploit results in device crashes and persistent service outages, impacting network availability and business operations. With a CVSS score of 7.5, the high severity rating reflects the potential for unauthenticated remote disruption of critical networking infrastructure.
Remediation
Immediate Action: Upgrade MikroTik RouterOS to version 7 or apply the appropriate vendor-supplied security updates to resolve the underlying flaw.
Proactive Monitoring: Monitor network infrastructure for unexpected reboots, service interruptions, and anomalous traffic targeting TCP port 445.
Compensating Controls: Restrict access to the SMB service by implementing firewall rules that block external or unauthorized access to TCP port 445.
Exploitation status
Public Exploit Available: Yes, an ExploitDB entry and public GitHub proof-of-concept repositories exist.
Analyst recommendation
Given the severity of the potential denial of service impact and the availability of public exploit code, administrators must prioritize upgrading affected MikroTik RouterOS instances to version 7 immediately. Restricting network access to the SMB service provides essential risk reduction until updates can be deployed.