Loading
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later.
Use CWE-787, Mikrotik vendor hub and Routeros product page to widen CVE-2017-20149 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-30799, CVE-2022-45313 and CVE-2024-54952 for nearby disclosures in the same product family.