farreqop.blogg.se

Mikrotik routeros firmware
Mikrotik routeros firmware













mikrotik routeros firmware

Sometimes you may need to remotely manage a RouterOS device using WinBox. Restrict WinBox access using the “Available From” list

mikrotik routeros firmware

If you manage your router using another method, such as SSH, and you don’t actually need WinBox access, you can simply disable the WinBox service. You may not need to do all of them to prevent this vulnerability, but the more locked down the router is, the better. Here are some options to prevent your RouterOS device from being exploited. However, there is a chance that this could be exploited from inside the LAN by a malicious user if your rules allow access on the LAN side.įor more information on the exploit, please read the forum post on the Mikrotik site:Īdvisory: Vulnerability exploiting the Winbox port This remote exploit relies on the WinBox service being accessible, so if you don’t have that enabled, or you are blocking it via a IP firewall rule, or are restricting users via the WinBox services ‘Available From’ list, you should be safe from this vulnerability effecting you. This will appear in the RouterOS logs, as a WinBox connection attempt that fails, and then a second attempt, which is successful. The remote user can then log in, and take control of the router. While it currently remains uncertain exactly how the exploit works, it would appear that a remote user can connect to the WinBox port (which is port 8291 by default), and download a user database file, without successfully authenticating. Version 6.42.1 for current (and v6.43rc4 for release candidate), has just been released, which has fixed this vulnerability, and should be upgraded to as soon as possible. This is currently effecting RouterOS versions v6.29 through to v6.42 in the current channel (and up to v6.43rc3 in the release candidate channel). It was discovered on the 23rd of April 2018, that there was a remote vulnerability being exploited in the wild, that is exploiting the Winbox service on RouterOS based devices (Mikrotik / Routerboard devices).















Mikrotik routeros firmware