High SEVERITY — Vulnerability

CVE-2024-27686 — Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (devic

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

Platform
MikroTik RouterOS
CVE Record
CVE-2024-27686
CVSS Score
7.5/10
Published
08 May 2026
Views
18
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Summary

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

Assessment

  • CVE: CVE-2024-27686
  • CVSS base score: 7.5
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Source: NVD record

References

Action

  • Verify affected systems against your inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until patched

MikroTik RouterOS — Related Advisories

VIEW ALL →