CVE-2019-3924

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/02/2019
Last modified:
15/08/2025

Description

MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defined network requests to both WAN and LAN clients. A remote unauthenticated attacker can use this vulnerability to bypass the router's firewall or for general network scanning activities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:* 6.42.12 (excluding)
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* 6.43.12 (excluding)