High [CVE-2023-32154] RouterOS: Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability.
This high-severity MikroTik advisory covers CVE-2023-32154 affecting MikroTik RouterOS.
Android app · Google Play
Monitor future MikroTik CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
On 10/05/2023 (May 10th, 2023) MikroTik received information about a new vulnerability, which is assigned the ID CVE-2023-32154. The report stated, that vendor (MikroTik) was contacted in December, but we did not find record of such communication.
The original report also says, that vendor was informed in person in an event in Toronto, where MikroTik was not present in any capacity. What this issue affects: The issue affects devices running MikroTik RouterOS versions v6.xx and v7.xx with enabled IPv6 advertisement receiver functionality.
You are only affected if one of the below settings is applied: ipv6/settings/ set accept-router-advertisements=yes or ipv6/settings/set forward=no accept-router-advertisements=yes-if-forwarding-disabled If the above settings are not set up like in the example, you are not affected.
Note that the vulnerable setting combination is not normally found in routers and is rarely used. What this issue can cause: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS.
Authentication is not required to exploit this vulnerability.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
- 7.9.1
- 6.49.8
- 6.48.7
- 7.10beta8
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- Upgrade RouterOS to a fixed release: 7.9.1, 6.49.8, 6.48.7, 7.10beta8.
- MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall to limit exposure to untrusted networks; for this specific issue, also review whether accepting IPv6 router advertisements is needed on the device.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.