An issue was discovered in the Winbox service of MikroTik...
Moderate severity
Unreviewed
Published
Feb 12, 2025
to the GitHub Advisory Database
•
Updated Feb 13, 2025
Description
Published by the National Vulnerability Database
Feb 11, 2025
Published to the GitHub Advisory Database
Feb 12, 2025
Last updated
Feb 13, 2025
An issue was discovered in the Winbox service of MikroTik RouterOS v6.43 through v7.16.1. A discrepancy in response times between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.
References