← Back to browse · API

CVE-2017-20149

Severity
CRITICAL
CVSS
9.8
EPSS
0.01919
Risk score
39.87
CISA KEV
No
PoC
No
Published
2022-10-15
Modified
2025-05-14
First seen
2026-08-07
Aliases
EUVD-2017-11155, GHSA-QJVR-7H9F-927V
Products
n/a:n/a n/a
Sources
euvd EUVD-2017-11155

Description

The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later.

References