Vulnerability
CVE-2020-20249
MEDIUM 6.5
CVE-2020-20249 is a medium-severity vulnerability (CVSS v3.1 6.5). As of 2026-10-08, 2 770 hosts in our data show software it affects on an open service in at least 15 countries.
Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenticated remote attacker can cause a Denial of Service.
- Published
- 2021-07-19
- Last modified
- 2026-06-17
- CVSS score
- 6.5 CVSS v3.1
- CVSS vector (v3.1)
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Exploit likelihood (EPSS)
- 1.8% in the next 30 days (higher than 77% of CVEs)
Exposure in our data
2 770 hosts
Hosts whose banner shows an affected software version on a service open at their latest check.
Not counted: 739 hosts with this CVE only from an older observation.
8 more hosts had it earlier (the software version has since changed or the service is gone).
Counted 2026-10-08 03:20 UTC
By country
| Russia RU | 631 |
| India IN | 187 |
| Iran IR | 164 |
| Ukraine UA | 164 |
| China CN | 154 |
| Brazil BR | 144 |
| United States US | 144 |
| Indonesia ID | 114 |
| Vietnam VN | 104 |
| Bangladesh BD | 98 |
| South Africa ZA | 84 |
| Thailand TH | 60 |
| Kazakhstan KZ | 53 |
| Yemen YE | 47 |
| Pakistan PK | 42 |
Affected software seen
| routeros 6.45.9 | 355 |
| routeros 6.44.5 | 155 |
| routeros 6.46.8 | 125 |
| routeros 6.45.8 | 91 |
| routeros 6.44.6 | 84 |
| routeros 6.46.4 | 74 |
| routeros 6.40.8 | 73 |
| routeros 6.46.6 | 70 |
| routeros 6.44.3 | 69 |
| routeros 6.42.12 | 68 |
| routeros 6.42.7 | 66 |
| routeros 6.45.6 | 58 |