VYPR
Medium severity5.4NVD Advisory· Published Feb 11, 2025· Updated Jun 17, 2026

CVE-2024-54772

CVE-2024-54772

Description

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Mikrotik/Routeros4 versions
    cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*+ 3 more
    • cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*range: >=6.43,<6.49.18
    • cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:*range: >=6.43.13,<=6.49.13
    • (no CPE)
    • (no CPE)range: v6.43.13 through v6.49.13, v6.43 through v7.17.2

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.