Vulnerability

CVE-2020-20249

MEDIUM 6.5

CVE-2020-20249 is a medium-severity vulnerability (CVSS v3.1 6.5). As of 2026-10-08, 2 770 hosts in our data show software it affects on an open service in at least 15 countries.

Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenticated remote attacker can cause a Denial of Service.

Published
2021-07-19
Last modified
2026-06-17
CVSS score
6.5 CVSS v3.1
CVSS vector (v3.1)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploit likelihood (EPSS)
1.8% in the next 30 days (higher than 77% of CVEs)

Exposure in our data

2 770 hosts

Hosts whose banner shows an affected software version on a service open at their latest check.

Not counted: 739 hosts with this CVE only from an older observation.

8 more hosts had it earlier (the software version has since changed or the service is gone).

Counted 2026-10-08 03:20 UTC

By country

Russia RU631
India IN187
Iran IR164
Ukraine UA164
China CN154
Brazil BR144
United States US144
Indonesia ID114
Vietnam VN104
Bangladesh BD98
South Africa ZA84
Thailand TH60
Kazakhstan KZ53
Yemen YE47
Pakistan PK42

Affected software seen

routeros 6.45.9355
routeros 6.44.5155
routeros 6.46.8125
routeros 6.45.891
routeros 6.44.684
routeros 6.46.474
routeros 6.40.873
routeros 6.46.670
routeros 6.44.369
routeros 6.42.1268
routeros 6.42.766
routeros 6.45.658