Medium severity6.5NVD Advisory· Published May 18, 2021· Updated Jun 17, 2026
CVE-2020-20254
CVE-2020-20254
Description
Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Affected products
3- Mikrotik/RouterOsdescription
Patches
Vulnerability mechanics
References
2- seclists.org/fulldisclosure/2021/May/14nvdExploitMailing ListThird Party Advisory
- github.com/cq674350529/pocs_slides/blob/master/pocs/MikroTik/vul_lcdstat_2/README.mdnvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.