The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://vulncheck.com/advisories/mikrotik-jsproxy-dos |
|
History
Fri, 21 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected. | The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected. |
| CPEs | cpe:2.3:o:mikrotik:routeros:6.48.8:*:*:*:*:*:*:* cpe:2.3:o:mikrotik:routeros:6.49.9:*:*:*:*:*:*:* |
Thu, 26 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2023-09-07T15:43:54.429Z
Updated: 2025-11-21T16:14:51.409Z
Reserved: 2023-04-18T10:31:45.962Z
Link: CVE-2023-30800
Updated: 2024-08-02T14:37:15.351Z
Status : Modified
Published: 2023-09-07T16:15:07.670
Modified: 2025-11-21T17:15:49.593
Link: CVE-2023-30800
No data.