VYPR
High severity7.5NVD Advisory· Published Feb 20, 2019· Updated Jun 17, 2026

CVE-2019-3924

CVE-2019-3924

Description

MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defined network requests to both WAN and LAN clients. A remote unauthenticated attacker can use this vulnerability to bypass the router's firewall or for general network scanning activities.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Mikrotik/Routeros3 versions
    cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*+ 2 more
    • cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*range: <6.43.12
    • cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:*range: <6.42.12
    • (no CPE)range: <6.43.12 (stable), <6.42.12 (long-term)
  • Tenable/MikroTik RouterOSv5
    Range: RouterOS long-term 6.42.11 and below, RouterOS stable 6.43.11 and below

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.