CVE-2019-15055
Last modified
CVE-2019-15055 is a vulnerability of currently unknown severity. MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication.. EPSS estimates a 2.23% chance of exploitation in the next 30 days.
Description
MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mikrotik | Routeros | <= 6.44.5 |
| Mikrotik | Routeros | >= 6.45, <= 6.45.3 |
References
- https://fortiguard.com/zeroday/FG-VD-19-108Third Party Advisory
- https://github.com/tenable/routeros/tree/master/poc/cve_2019_15055Exploit, Third Party Advisory
- https://medium.com/tenable-techblog/rooting-routeros-with-a-usb-drive-16d7b8665f90Press/Media Coverage, Third Party Advisory
- https://mikrotik.com/download/changelogs/testing-release-treeRelease Notes, Vendor Advisory
- https://fortiguard.com/zeroday/FG-VD-19-108Third Party Advisory
- https://github.com/tenable/routeros/tree/master/poc/cve_2019_15055Exploit, Third Party Advisory
- https://medium.com/tenable-techblog/rooting-routeros-with-a-usb-drive-16d7b8665f90Press/Media Coverage, Third Party Advisory
- https://mikrotik.com/download/changelogs/testing-release-treeRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-15055?
How severe is CVE-2019-15055?
How do I fix CVE-2019-15055?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1505Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-15050An issue was discovered in Bento4 1.5.1.0. There is a heap-b…
- CVE-2019-15051An issue was discovered in Softing uaGate (SI, MB, 840D) fir…8.8
- CVE-2019-15052The HTTP client in Gradle before 5.6 sends authentication cr…9.8
- CVE-2019-15053The "HTML Include and replace macro" plugin before 1.5.0 for…
- CVE-2019-15054Multiple cross-site scripting (XSS) vulnerabilities in Mailb…6.1
- CVE-2019-15058stb_image.h (aka the stb image loader) 2.23 has a heap-based…
- CVE-2019-15059In Liberty lisPBX 2.0-4, configuration backup files can be r…7.5
- CVE-2019-1506Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-15060The traceroute function on the TP-Link TL-WR840N v4 router w…
- CVE-2019-15062An issue was discovered in Dolibarr 11.0.0-alpha. A user can…
- CVE-2019-15064HiNet GPON firmware version < I040GWR190731 allows an attack…9.8
Are you affected by CVE-2019-15055?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
