PT-2025-23197 · Mikrotik · Mikrotik Routeros

CVE-2024-54952

·

Published

2024-11-21

·

Updated

2025-06-30

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MikroTik RouterOS version 6.40.5
Description The SMB service in MikroTik RouterOS contains a memory corruption issue. Remote, unauthenticated attackers can exploit this by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Service (DoS), rendering the SMB service unavailable.
Recommendations For MikroTik RouterOS version 6.40.5, consider disabling the SMB service until a patch is available to prevent Remote Denial of Service (DoS) attacks.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06641
CVE-2024-54952

Affected Products

Mikrotik Routeros