cbcvebase.

Mikrotik Routeros vulnerabilities

99 known vulnerabilities affecting mikrotik/routeros.

Total CVEs
99
CISA KEV
5
actively exploited
Public exploits
16
Exploited in wild
10
Severity breakdown
CRITICAL8HIGH35MEDIUM55LOW1

Vulnerabilities

Page 1 of 5
CVE-2018-14847P1CRITICALCVSS 9.1KEVPoC≤ 6.422018-08-02
CVE-2018-14847 [CRITICAL] CWE-22 CVE-2018-14847: MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and r MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
nvd
CVE-2018-7445P1CRITICALCVSS 9.8KEVPoCfixed in 6.41.3v6.42-rc11+11 more2018-03-19
CVE-2018-7445 [CRITICAL] CWE-119 CVE-2018-7445: A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session req A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit
nvd
CVE-2026-86060P1CRITICALCVSS 9.8KEVPoC≥ 6.0, < 6.49.21≥ 7.0, < 7.23.4+3 more2026-09-05
CVE-2026-86060 [CRITICAL] CWE-88 CVE-2026-86060: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin wit RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21
nvd
CVE-2026-67279P1MEDIUMCVSS 6.5KEVPoC≥ 6.0, < 6.49.21≥ 7.0, < 7.23.4+3 more2026-09-05
CVE-2026-67279 [MEDIUM] CWE-841 CVE-2026-67279: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authenti RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the R
nvd
CVE-2026-67277P1HIGHCVSS 8.2KEV≥ 6.0, < 6.49.21≥ 7.0, < 7.23.4+3 more2026-09-05
CVE-2026-67277 [HIGH] CWE-306 CVE-2026-67277: RouterOS accepts a "related" btest connection before the corresponding primary session has completed RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigne
nvd
CVE-2017-20149P1CRITICALCVSS 9.8ExploitedPoCfixed in 6.37.5≥ 6.38, < 6.38.52022-10-15
CVE-2017-20149 [CRITICAL] CWE-787 CVE-2017-20149: The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long- The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-
nvd
CVE-2026-67276P1HIGHCVSS 8.1ExploitedPoC≥ 7.9, < 7.23.4≥ 7.24, < 7.24.22026-09-05
CVE-2026-67276 [HIGH] CWE-347 CVE-2026-67276: RouterOS does not compare the complete RSA public key when matching an SSH authentication request to RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature,
nvd
CVE-2023-30799P2HIGHCVSS 7.2ExploitedPoC≤ 6.48.7≥ 6.34, < 6.49.7+1 more2023-07-19
CVE-2023-30799 [HIGH] CWE-269 CVE-2023-30799: MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege es MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
nvd
CVE-2019-3978P2HIGHCVSS 7.5ExploitedPoC≤ 6.44.5≤ 6.45.62019-10-29
CVE-2019-3978 [HIGH] CWE-306 CVE-2019-3978: RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS responses are cached by the router, potentially resulting in cache poisoning
nvd
CVE-2019-3924P2HIGHCVSS 7.5PoCfixed in 6.42.12fixed in 6.43.122019-02-20
CVE-2019-3924 [HIGH] CWE-441 CVE-2019-3924: MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary v MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defined network requests to both WAN and LAN clients. A remote unauthenticated attacker can use this vulnerability to bypass the router's firewall or for general network scanning activities.
nvd
CVE-2017-7285P2HIGHCVSS 7.5PoCv6.38.52017-03-29
CVE-2017-7285 [HIGH] CWE-400 CVE-2017-7285: A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an u A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP connections.
nvd
CVE-2019-3977P3HIGHCVSS 7.5Exploited≤ 6.44.5≤ 6.45.62019-10-29
CVE-2019-3977 [HIGH] CWE-494 CVE-2019-3977: RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade p RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download from when using the autoupgrade feature. Therefore, a remote attacker can trick the router into "upgrading" to an older version of RouterOS and possibly reseting all the system's usernames and passwords.
nvd
CVE-2021-27221P3HIGHCVSS 8.1PoCv6.47.92021-03-19
CVE-2021-27221 [HIGH] CVE-2021-27221: MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work
nvd
CVE-2017-6444P3HIGHCVSS 7.5PoCv6.252017-03-12
CVE-2017-6444 [HIGH] CWE-400 CVE-2017-6444: The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets. After the attacker stops the exploit, the CPU usage is 100% and the router requires a reboot for normal operation
nvd
CVE-2019-3943P3HIGHCVSS 8.1PoC≤ 6.42.12≤ 6.43.12+7 more2019-04-10
CVE-2019-3943 [HIGH] CWE-23 CVE-2019-3943: MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44be MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read and write files outside of the sandbox directory (/rw/disk).
nvd
CVE-2026-84411P2CRITICALCVSS 9.8fixed in 7.242026-10-02
CVE-2026-84411 [CRITICAL] CWE-191 CVE-2026-84411: The web management service in affected RouterOS versions contains an integer underflow in its HTTP r The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
nvd
CVE-2008-6976P3MEDIUMCVSS 6.4PoC≥ 2.0, ≤ 2.9.51≥ 3.0, ≤ 3.132009-08-19
CVE-2008-6976 [MEDIUM] CWE-20 CVE-2008-6976: MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.
nvd
CVE-2021-41987P2HIGHCVSS 8.1v6.46.8v6.47.9+1 more2022-03-16
CVE-2021-41987 [HIGH] CWE-787 CVE-2021-41987: In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based bu In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects RouterOS 6.46.8, 6.47.9, and 6.47.10.
nvd
CVE-2026-67278P2CRITICALCVSS 9.1≥ 7.0, < 7.23.6≥ 7.24, < 7.24.3+1 more2026-09-05
CVE-2026-67278 [CRITICAL] CWE-347 CVE-2026-67278: MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private
nvd
CVE-2025-10948P2HIGHCVSS 8.8v72025-09-25
CVE-2025-10948 [HIGH] CWE-119 CVE-2025-10948: A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.20.1 and 7.
nvd
Mikrotik Routeros vulnerabilities | cvebase