MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defined network requests to both WAN and LAN clients. A remote unauthenticated attacker can use this vulnerability to bypass the router's firewall or for general network scanning activities.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Aug 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* | |
Metrics |
cvssV3_0
|
cvssV3_1
|

Status: PUBLISHED
Assigner: tenable
Published: 2019-02-20T20:00:00Z
Updated: 2024-09-17T02:46:52.071Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-3924

No data.

Status : Analyzed
Published: 2019-02-20T20:29:03.047
Modified: 2025-08-15T20:21:44.360
Link: CVE-2019-3924

No data.