← Global Threat Landscape
CVE-2018-7445
CWE-119
Critical
103.4
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.
Source: NVD
Signals
- CVSS
- 9.8
- Critical · v3.1
- EPSS
- 60.80%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Sept 2022
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-119
- Published
- 19 Mar 2018
- Last modified 7 Nov 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2018-7445Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time