CVE-2017-8338: MikroTik RouterOS

High severity, CVSS 7.5. EPSS: 4.2% chance of exploitation in the next 30 days.

A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all devices will be disconnected from the router and all logs removed automatically.

Affected products

Published 2017-05-18. Last modified 2026-06-17.