A vulnerability in the Winbox service of MikroTik RouterOS (long-term v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2) allows remote attackers to enumerate valid usernames. The service responds with a different response size depending on whether a valid or invalid username is supplied during connection attempts, enabling attackers to determine which usernames exist on the device. The issue is patched in stable release v6.49.18.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Rust proof-of-concept exploit for CVE-2024-54772, a vulnerability in MikroTik RouterOS that allows remote enumeration of valid usernames via the Winbox service (TCP port 8291). The main exploit logic is implemented in 'src/main.rs', which crafts a specific binary payload containing a username and sends it to the target router. By analyzing the size of the response, the exploit determines whether the username is valid (51 bytes) or invalid (35 bytes). The code is straightforward, with the target IP and port hardcoded to the default MikroTik router address (192.168.88.1:8291) and the username set to 'admin' by default. The repository is structured as a simple Rust project with standard configuration files and a single source file implementing the exploit logic. No external dependencies are used, and the exploit is not weaponized or part of a larger framework.
This repository provides a proof-of-concept exploit for CVE-2024-54772, a username enumeration vulnerability in MikroTik RouterOS. The exploit targets the Winbox service running on TCP port 8291. There are two main Python scripts: 1. 'mikrotik_routeros_username_enum.py' - Takes a single username and a target IP, crafts a binary payload with the username, sends it to the target on port 8291, and determines if the username is valid based on the length of the response (51 bytes for valid, 35 bytes for invalid). 2. 'mikrotik_routeros_username_enum_wordlist.py' - Takes a wordlist and a list of target IPs, and performs the same enumeration in an asynchronous manner, reporting all valid usernames found for each target. The exploit is effective against RouterOS stable versions v6.43 through v7.17.2 and long-term v6.43.13 through v6.49.13. The repository includes a README with usage instructions, affected versions, and references. No hardcoded IPs or domains are present; the only fingerprintable endpoint is TCP port 8291 on the target device. The exploit is a POC and does not provide post-exploitation capabilities.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.