CyberRota Analysis
AI-GeneratedRouterOS is vulnerable due to its acceptance of "related" btest connections before the primary session's authentication is complete, allowing unauthenticated clients to initiate an IPv4 UDP test. This can lead to an unsigned integer underflow and anomalously large fragmented output, potentially causing a kernel restart and disrupting network services. Organizations using affected versions of RouterOS should prioritize patching to versions 6.49.21, 7.23.4, or 7.24.2 to mitigate this high-severity vulnerability.
Original NVD Description
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Related CVEs
Other vulnerabilities affecting the same vendor(s)