CVE-2024-54772

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.
CVSS

No CVSS.

References
Link Resource
https://github.com/deauther890/CVE-2024-54772 Third Party Advisory Exploit
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*
cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:*
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*

History

30 Jun 2025, 14:48

Type Values Removed Values Added
References () https://github.com/deauther890/CVE-2024-54772 - () https://github.com/deauther890/CVE-2024-54772 - Third Party Advisory, Exploit
CPE cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:*
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*
First Time Mikrotik routeros
Mikrotik

24 Feb 2025, 16:15

Type Values Removed Values Added
Summary An issue was discovered in the Winbox service of MikroTik RouterOS v6.43 through v7.16.1. A discrepancy in response times between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts. An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.

11 Feb 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 23:15

Updated : 2025-06-30 14:48


NVD link : CVE-2024-54772

Mitre link : CVE-2024-54772


JSON object : View

Products Affected

mikrotik

  • routeros
CWE

No CWE.