CVE-2017-7285: MikroTik RouterOS

High severity, CVSS 7.5. EPSS: 19.3% chance of exploitation in the next 30 days.

A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP connections.

Affected products

Published 2017-03-29. Last modified 2026-06-17.