MikroTik Routeros
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in MikroTik Routeros.
Known Exploited MikroTik Routeros Vulnerabilities
The following MikroTik Routeros vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability |
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. CVE-2026-67279 |
September 25, 2026 |
| MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability |
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. CVE-2026-86060 |
September 10, 2026 |
| MikroTik RouterOS Missing Authentication for Critical Function Vulnerability |
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. CVE-2026-67277 |
September 10, 2026 |
| MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability |
In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. CVE-2018-7445 Exploit Probability: 60.8% |
September 8, 2022 |
| MikroTik Router OS Directory Traversal Vulnerability |
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface. CVE-2018-14847 Exploit Probability: 96.0% |
December 1, 2021 |
Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 19 vulnerabilities in MikroTik Routeros with an average score of 7.4 out of ten. Last year, in 2025 Routeros had 7 security vulnerabilities published. That is, 12 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.99
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 19 | 7.44 |
| 2025 | 7 | 8.43 |
| 2024 | 1 | 0.00 |
| 2023 | 6 | 7.84 |
| 2022 | 11 | 8.03 |
| 2021 | 34 | 6.54 |
| 2020 | 3 | 5.60 |
| 2019 | 9 | 7.82 |
| 2018 | 7 | 7.87 |
It may take a day or so for new Routeros vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent MikroTik Routeros Security Vulnerabilities
RouterOS Integer Underflow in HTTP Body Enables Root Code Exec
CVE-2026-84411
9.8 - Critical
- October 02, 2026
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Integer underflow
RouterOS <7.25beta4: Improper input validation in BGP VPN NLRI (Crash)
CVE-2026-93345
8.7 - High
- September 22, 2026
MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which passes validation while describing a route with a negative-length address portion. Attackers can repeatedly send a single BGP UPDATE packet carrying a VPNv4 or VPNv6 NLRI with an out-of-bounds prefix-length to indefinitely hold down the BGP plane, causing session termination without a NOTIFICATION and triggering a service malfunction on the device. The fix is carried only in 7.25beta4, a development build; the current stable release 7.24.2 and the current long-term release 7.23.5 both remain affected.
Improper Validation of Specified Quantity in Input
MikroTik RouterOS <7.24 SMB1 Heap Corruption via uniPwdLen Underflow
CVE-2026-89028
8.2 - High
- September 16, 2026
MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, causing the resulting value to be used as the copy length in a memory copy operation into a smaller heap buffer, corrupting adjacent heap memory.
Heap-based Buffer Overflow
MikroTik RouterOS <7.24 SMB OOB Read Vulnerability
CVE-2026-56719
6.3 - Medium
- September 16, 2026
MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
Out-of-bounds Read
Cleartext Credential Leak in Mikrotik RouterOS 7.19.4 via SPI Flash Dump
CVE-2025-56566
4.6 - Medium
- September 16, 2026
MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authenticating to the device and without knowledge of the administrative password.
Cleartext Storage of Sensitive Information
MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction
CVE-2026-89021
6.9 - Medium
- September 14, 2026
MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical. The vendor has confirmed that the issue is not resolved in the long-term release and that the fix is carried forward only in the stable branch from 7.24.2 onward, with no backport to the long-term branch planned.
insecure temporary file
MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function
CVE-2026-89020
5.3 - Medium
- September 14, 2026
MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to the /tool fetch command; the first write outside the 528-byte buffer occurs at 505 bytes. Attackers can trigger the overflow by issuing a fetch command with a crafted tftp:// URL path, which causes an unbounded rep movsb instruction to overwrite saved registers at a deterministic offset, crashing the process without requiring a reachable TFTP server or elevated privileges beyond read-only group membership.
Stack Overflow
RouterOS 6.x/7.x Privilege Escalation via Username Arg Flip in SSH
CVE-2026-86060
9.2 - Critical
- September 05, 2026
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Argument Injection
RouterOS SSH Rekey Escalation Enables Unauthenticated Exec in 6.x/7.x
CVE-2026-67279
6.9 - Medium
- September 05, 2026
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Improper Enforcement of Behavioral Workflow
RouterOS WebFig Unauth File-Read via /jsproxy Stale Pointer (6.49.21+)
CVE-2026-67281
8.7 - High
- September 05, 2026
RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)
Access of Uninitialized Pointer
MikroTik RouterOS TLS Forgery: RSA PKCS#1 v1.5 Signature (e=3) Pre-6.49.21
CVE-2026-67278
6.3 - Medium
- September 05, 2026
MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the roots public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. The same permissive verification also undermines RSA-based SSH authentication. This issue affects only 7.x branch was fixed in versions: 7.23.6 (Long-term) and 7.24.3 (Stable). Releases 7.23.4 and 7.24.2 included an incomplete fix.
Improper Verification of Cryptographic Signature
RouterOS: btest Conn Auth Gap & IPv4 UDP Test Int Underflow (7.24.2)
CVE-2026-67277
8.8 - High
- September 05, 2026
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Missing Authentication for Critical Function
RouterOS RSA Exponent Omission Enables SSH Auth Bypass (pre-6.49.21/7.23.4/7.24.2)
CVE-2026-67276
9.2 - Critical
- September 05, 2026
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)
Improper Verification of Cryptographic Signature
RouterOS API Insufficient Session Exp Exp (CVE-2026-14227)
CVE-2026-14227
4.9 - Medium
- July 30, 2026
An API sessionmanagement flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or usergroup changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.
Insufficient Session Expiration
MikroTik RouterOS API lacks ratelimiting, enabling bruteforce attacks
CVE-2026-16347
8.8 - High
- July 28, 2026
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.
Improper Restriction of Excessive Authentication Attempts
DoS via libumsg.so unflatten() in MikroTik RouterOS 7.21.x before 7.21.4
CVE-2026-39042
7.5 - High
- July 13, 2026
An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.
Integer Overflow or Wraparound
Mikrotik RouterOS SMB DoS v6.40-6.49 (fixed in 7)
CVE-2024-27686
7.5 - High
- May 08, 2026
Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.
Resource Exhaustion
RouterOS <=6.47 cert validation bypass via shared trust store
CVE-2025-42611
6.5 - Medium
- May 05, 2026
RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerability lies in shared certificate validation logic which uses the system certificate store that is shared and equally trusted by all system services. This causes confusion of scope, allowing any certificate authority present in the system-wide trust store to be trusted in any context (with some exceptions), allowing partial or full authentication bypass in CAPsMAN, OpenVPN, Dot1X and potentially others.
Improper Certificate Validation
MikroTik RouterOS 6.49.8 OOB Read in SCEP Endpoint (ASN1_STRING_data)
CVE-2026-7668
7.3 - High
- May 02, 2026
A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The exploit is publicly available and might be used. You should upgrade the affected component. The vendor recommends to "use the latest v6.x or 7.x MikroTik RouterOS version, the reported issue should be fixed there."
Out-of-bounds Read
RouterOS 7.14.2 RCE via HTTP-Only WebFig
CVE-2025-61481
10 - Critical
- October 27, 2025
An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrators browser and intercept credentials.
Insecure Default Initialization of Resource
RouterOS 7 BOF via parse_json_element in libjson.so
CVE-2025-10948
8.8 - High
- September 25, 2025
A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.20.1 and 7.21beta2 mitigates this issue. You should upgrade the affected component. The vendor replied: "Our bug tracker reports that your issue has been fixed. This means that we plan to release a RouterOS update with this fix. Make sure to upgrade to the next release when it comes out."
Classic Buffer Overflow
MikroTik RouterOS XSS via hotspot dst <7.19.2
CVE-2025-6563
- July 03, 2025
A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victim browses to the malicious URL and logs in, the XSS executes. The POST request used to login, can also be converted to a GET request, allowing an attacker to send a specifically crafted URL that automatically logs in the victim (into the attacker's account) and triggers the payload.
RouterOS 7 before v7.14 allows IPv6 UDP traceroute
CVE-2023-47310
6.5 - Medium
- June 30, 2025
A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets.
ASP.NET Misconfiguration: Improper Model Validation
RouterOS VXLAN Source IP Improper Access Control
CVE-2025-6443
- June 25, 2025
Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of remote IP addresses when processing VXLAN traffic. The issue results from the lack of validation of the remote IP address against configured values prior to allowing ingress traffic into the internal network. An attacker can leverage this vulnerability to gain access to internal network resources. Was ZDI-CAN-26415.
Authorization
MikroTik RouterOS 6.40.5 SMB memory corruption DoS
CVE-2024-54952
- May 29, 2025
MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Service (DoS), rendering the SMB service unavailable.
MikroTik RouterOS Winbox Account Enumeration v6.43v7.17.2 Fixed in 6.49.18
CVE-2024-54772
- February 11, 2025
An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.
RouterOS RADVD OOB Write Allows RCE (CVE-2023-32154)
CVE-2023-32154
- May 03, 2024
Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Router Advertisement Daemon. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-19797.
MikroTik RouterOS 7.1-7.11 Rest API Access Control Flaw
CVE-2023-41570
5.3 - Medium
- November 14, 2023
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
Heap Memory Corruption in MikroTik RouterOS 6 Web Server (Fixed in 6.49.10)
CVE-2023-30800
7.5 - High
- September 07, 2023
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.
Memory Corruption
MikroTik RouterOS <=6.48.6 PrivPriv Esc via Winbox/HTTP Arbitrary Code Exec
CVE-2023-30799
9.1 - Critical
- July 19, 2023
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
Improper Privilege Management
MikroTik RouterOS <=6.46.3 SSH Daemon DoS via Misconfig
CVE-2020-20021
- July 12, 2023
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.
DoS via crafted packets in MikroTik RouterOS v6.40.5 bridge2 component
CVE-2023-24094
7.5 - High
- March 27, 2023
An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets.
Memory Corruption
Mikrotik RouterOS Unauth RCE via Writable Config Backend
CVE-2022-45140
9.8 - Critical
- February 27, 2023
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
Missing Authentication for Critical Function
Mikrotik RouterOS <7.5 OOB Read in Hotspot Arbitrary Code Exec via Crafted Nova
CVE-2022-45313
8.8 - High
- December 05, 2022
Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message.
Out-of-bounds Read
Mikrotik RouterOS <v7.6 Snmp OOB Read Arbitrary Code (CVE-2022-45315)
CVE-2022-45315
9.8 - Critical
- December 05, 2022
Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated attackers to execute arbitrary code via a crafted packet.
Out-of-bounds Read
Mikrotik RouterOS <6.38.5/6.37.5 Web Server Mem Corruption
CVE-2017-20149
9.8 - Critical
- October 15, 2022
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later.
Memory Corruption
DoS via crafted packet in Mikrotik RouterOS 6.48.3 netwatch
CVE-2022-36522
6.5 - Medium
- August 26, 2022
Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
assertion failure
MikroTik RouterOS 7.4beta4 container pkg mount symlink flaw
CVE-2022-34960
9.8 - Critical
- August 25, 2022
The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.
insecure temporary file
MikroTik RouterOS SSL/TLS Renegotiation DoS Vulnerability
CVE-2022-36324
7.5 - High
- August 10, 2022
Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.
Allocation of Resources Without Limits or Throttling
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process
CVE-2021-36613
6.5 - Medium
- May 11, 2022
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
NULL Pointer Dereference
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process
CVE-2021-36614
6.5 - Medium
- May 11, 2022
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
NULL Pointer Dereference
In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow
CVE-2021-41987
8.1 - High
- March 16, 2022
In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects RouterOS 6.46.8, 6.47.9, and 6.47.10.
Memory Corruption
A buffer overflow in Mikrotik RouterOS 6.47
CVE-2020-22844
7.5 - High
- February 28, 2022
A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.
Memory Leak
A buffer overflow in Mikrotik RouterOS 6.47
CVE-2020-22845
7.5 - High
- February 28, 2022
A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted FTP requests.
Classic Buffer Overflow
Mikrotik RouterOs before 6.47 (stable tree) suffers
CVE-2020-20262
6.5 - Medium
- July 21, 2021
Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.
assertion failure
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process
CVE-2020-20219
6.5 - Medium
- July 21, 2021
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Memory Corruption
Mikrotik RouterOs before 6.44.6 (long-term tree) suffers
CVE-2020-20221
6.5 - Medium
- July 21, 2021
Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.
Resource Exhaustion
Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process
CVE-2020-20249
6.5 - Medium
- July 19, 2021
Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenticated remote attacker can cause a Denial of Service.
Buffer Overflow
Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process
CVE-2020-20248
6.5 - Medium
- July 19, 2021
Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.
Resource Exhaustion
Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process
CVE-2020-20230
6.5 - Medium
- July 19, 2021
Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.
Resource Exhaustion
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for MikroTik Routeros or by MikroTik? Click the Watch button to subscribe.