VYPR
Medium severity6.5NVD Advisory· Published May 18, 2021· Updated Jun 17, 2026

CVE-2020-20254

CVE-2020-20254

Description

Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

Affected products

3
  • Mikrotik/Routeros2 versions
    cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*range: <6.47
    • (no CPE)range: <6.47
  • Mikrotik/RouterOsdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.