cvedb.io
CVE-2024-54772
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2025-02-11T23:15:09.117 · Last modified 2026-06-17T08:10:40.837

Summary

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.

Affected products

mikrotik — routeros

Does this affect you?

Add your gear to cvedb and we'll alert you only when mikrotik ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.