CVE-2019-3976(mikrotik / routeros)

LOWCVSS 8.8 ยท HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerability via the upgrade package's name field. If an authenticated user installs a malicious package then a directory could be created and the developer shell could be enabled.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • routeros

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
routeros

Deep dive

Activity timeline1 mentions / 1d
00111Mentions ยท 2026-09-27: 109-27
Full discourse1 post
  • General Intels Daily@intels_daily

    ๐Ÿ”ด ๐—–๐—ฅ๐—œ๐—ง๐—œ๐—–๐—”๐—Ÿ ยท ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐˜€๐—ฎ๐—น๐—ฒ ๐Ÿข Target: ๐—•๐—ฎ๐—ป๐—ด๐—น๐—ฎ๐—ฑ๐—ฒ๐˜€๐—ต ๐—”๐—ฟ๐—บ๐˜† ๐Ÿงฉ Product: ๐— ๐—ถ๐—ธ๐—ฟ๐—ผ๐—ง๐—ถ๐—ธ ๐—ฅ๐—ผ๐˜‚๐˜๐—ฒ๐—ฟ๐—ข๐—ฆ ๐Ÿ›ก๏ธ CVE-2018-14847, CVE-2019-3976 A threat actor claims to have fully compromised the Bangladesh Army network, specifically targeting a MikroTik router at the Qadirabad Cantonment. The actor provides extensive technical details, including internal network maps, device lists, PPPoE connections, and backup files containing passwords, and offers this access for sale. #AccessSale #InitialAccess #ThreatIntel #CTI

    0000030
    674 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmikrotikrouteros---
OSmikrotikrouteros---

Explore more