{"id":"CVE-2017-17537","title":"MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and sending data that begins with many '\\0' characters, possibly related to DNS.","summary":"MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and sending data that begins with many '\\0' characters, possibly related to DNS.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"vendor":"mikrotik","product":"routerboard","affected":["routerboard = 6.39.2","routerboard = 6.40.5"],"published":"2017-12-13","updated":"2026-09-16","sourceUpdated":"2026-09-16T21:17:04.613","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2017-17537","references":[{"url":"https://packetstorm.news/files/id/145382","label":"cve@mitre.org"},{"url":"https://www.exploit-db.com/exploits/43200/","label":"cve@mitre.org"},{"url":"https://www.exploit-db.com/exploits/43200/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"epss":0.0165,"epssPercentile":0.75077,"ingestedAt":"2026-09-16T21:05:36.877Z","slug":"CVE-2017-17537","body":"## Overview\n\nMikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and sending data that begins with many '\\0' characters, possibly related to DNS.\n\n## Affected\n\n- `routerboard = 6.39.2`\n- `routerboard = 6.40.5`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[{"seq":205791,"id":"CVE-2017-17537","ts":1789596445361,"field":"cvss","old":null,"new":"7.5"},{"seq":205790,"id":"CVE-2017-17537","ts":1789596445361,"field":"severity","old":"none","new":"high"}]}