4 ms·
damn, enterprise I used to work at uses mikrotik for critical services...
by sudouser 8y ago
damn, enterprise I used to work at uses mikrotik for critical services...
- pilsetnieks 8y agoSo critical that they'd leave the web interface running on public IPs without firewalling? If not then they're probably safe.
- dboreham 8y agoIs it known that the vulnerability is in the web UI? I ask because the CERT report advised to disable/ACL web UI but it didn't (afaik) say that this was the attach vector. They might have just thrown that in as sound general advice.
- frankzinger 8y agoFrom their official forum post[1]: "Your devices are safe if the port 80 is firewalled, or if you have upgraded to v6.38.5 or newer." [1] https://forum.mikrotik.com/viewtopic.php?f=21&t=132499 https://forum.mikrotik.com/viewtopic.php?f=21&t=132499