A critical vulnerability (CVE-2023-32154) has been identified in RouterOS, the operating system used in MikroTik routers, allowing an unauthenticated user to remotely execute code on the device by sending a specially crafted IPv6 router advertisement (RA).
The issue is caused by the lack of proper validation of incoming data during the processing of IPv6 RA (Router Advertisement) requests, which allowed for data to be written outside the allocated buffer and to execute their code with root privileges. The vulnerability is present in branches of MikroTik RouterOS v6.xx and v7.xx when settings for receiving IPv6 RA messages are enabled (‘ipv6/settings/set accept-router-advertisements=yes’ or ‘ipv6/settings/set forward=no accept-router-advertisements=yes-if-forwarding-disabled’).
The practical exploitability of the vulnerability was demonstrated at the Pwn2Own competition in Toronto, where the researchers who uncovered the problem received a reward of $100,000 for a multi-stage breach of the infrastructure, attacking the MikroTik router and using it as a launchpad to attack other components of the local network (subsequently, the attackers gained control of a Canon printer, vulnerabilities for which were also disclosed).
Information about the vulnerability was initially published prior to a patch being provided by the manufacturer (0-day), but updates for RouterOS 7.9.1, 6.49.8, 6.48.7, and 7.10beta8 have since been released to fix the issue. According to the Zero Day Initiative (ZDI), the organization conducting the Pwn2Own competition, the manufacturer was notified of the vulnerability on December 29, 2022. Representatives from MikroTik claim they did not receive any notification and only learned of the problem on May 10, after a final disclosure warning was sent. Additionally, the vulnerability report mentions that details of the issue were conveyed to a MikroTik representative privately during the Pwn2Own competition in Toronto, but MikroTik has stated that no company staff participated in the event in any capacity.
Source: opennet.ru
