CVE-2024-54952

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
29/05/2025
Last modified:
30/06/2025

Description

MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Service (DoS), rendering the SMB service unavailable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mikrotik:routeros:6.40.5:*:*:*:-:*:*:*


References to Advisories, Solutions, and Tools