CVE-2017-8338: MikroTik RouterOS
High severity, CVSS 7.5. EPSS: 4.2% chance of exploitation in the next 30 days.
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all devices will be disconnected from the router and all logs removed automatically.
Affected products
- MikroTik RouterOS: version 6.38.5 only
Published 2017-05-18. Last modified 2026-06-17.