Impact
An integer overflow vulnerability in MikroTik RouterOS Release 7.21.x versions earlier than 7.21.4 and 7.22.x earlier than 7.22.2 allows an attacker to force the "unflatten()" function in libumsg.so to crash, resulting in a complete restart of the RouterOS service. The failure interrupts network services and can lead to significant disruption in environments that rely on continuous routing or firewall protection. The weakness is a classic integer overflow that corrupts memory during IPC message processing.
Affected Systems
The affected products are MikroTik RouterOS operating systems. Specifically, all RouterOS Release 7.21.x versions preceding 7.21.4 and all RouterOS Release 7.22.x versions preceding 7.22.2 are impacted. No earlier releases are affected, and all releases after 7.22.2 include the patch.
Risk and Exploitability
The CVSS score is 7.5. The EPSS score is less than 1%, indicating a low yet nonzero likelihood of exploitation. Based on the description, it is inferred that the vulnerability can be exploited remotely, requiring the attacker to send a crafted IPC message over the network. Because the attack can be performed from any external host and does not require elevated privileges, its potential impact is significant for exposed devices. The vulnerability is not listed in the CISA KEV catalog. This combination of moderate-to-high severity, low exploitation probability, and negative impact on availability underscores the need for timely patching.
OpenCVE Enrichment