Mikrotik Routeros vulnerabilities
99 known vulnerabilities affecting mikrotik/routeros.
Total CVEs
99
CISA KEV
5
actively exploited
Public exploits
16
Exploited in wild
10
Severity breakdown
CRITICAL8HIGH35MEDIUM55LOW1
Vulnerabilities
Page 2 of 5
CVE-2026-16347P3HIGHCVSS 8.8vAll versions2026-07-28
CVE-2026-16347 [HIGH] CWE-307 CVE-2026-16347: MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safegu
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-co
nvd
CVE-2018-1156P3HIGHCVSS 8.8fixed in 6.40.9fixed in 6.42.72018-08-23
CVE-2018-1156 [HIGH] CWE-787 CVE-2018-1156: Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to stack buffer overflow through the licens
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to stack buffer overflow through the license upgrade interface. This vulnerability could theoretically allow a remote authenticated attacker execute arbitrary code on the system.
nvd
CVE-2012-6050P3MEDIUMCVSS 6.4PoCv5.152012-11-27
CVE-2012-6050 [MEDIUM] CWE-16 CVE-2012-6050: The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial o
The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request to download the router's DLLs or plugins, as demonstrated by roteros.dll.
nvd
CVE-2022-34960P3CRITICALCVSS 9.8v7.42022-08-25
CVE-2022-34960 [CRITICAL] CWE-59 CVE-2022-34960: The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointi
The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.
nvd
CVE-2026-67281P3HIGHCVSS 7.5≥ 7.20, < 7.23.4≥ 7.24, < 7.24.22026-09-05
CVE-2026-67281 [HIGH] CWE-22 CVE-2026-67281: RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a new
RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-dir
nvd
CVE-2019-3976P3HIGHCVSS 8.8≤ 6.44.5≤ 6.45.62019-10-29
CVE-2019-3976 [HIGH] CWE-23 CVE-2019-3976: RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary director
RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerability via the upgrade package's name field. If an authenticated user installs a malicious package then a directory could be created and the developer shell could be enabled.
nvd
CVE-2022-45313P3HIGHCVSS 8.8fixed in 7.52022-12-05
CVE-2022-45313 [HIGH] CWE-125 CVE-2022-45313: Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot
Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message.
nvd
CVE-2022-45315P3CRITICALCVSS 9.8fixed in 7.62022-12-05
CVE-2022-45315 [CRITICAL] CWE-125 CVE-2022-45315: Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp pro
Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated attackers to execute arbitrary code via a crafted packet.
nvd
CVE-2023-32154P3HIGHCVSS 7.5fixed in 6.48.7v6.49.7 Stable2024-05-03
CVE-2023-32154 [HIGH] CWE-787 CVE-2023-32154: Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability
Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the Router Advertisement Daemon. The issue results
nvd
CVE-2025-6443P3HIGHCVSS 7.2fixed in 7.20v7.15.3, 7.16.22025-06-25
CVE-2025-6443 [HIGH] CWE-284 CVE-2025-6443: Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows r
Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of remote IP addresses when processing VXLAN traffic.
nvd
CVE-2023-30800P3HIGHCVSS 7.5≥ 6.0, < 6.49.10v6.49.9+1 more2023-09-07
CVE-2023-30800 [HIGH] CWE-787 CVE-2023-30800: The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not aff
nvd
CVE-2026-7668P3HIGHCVSS 7.3v6.49.82026-05-02
CVE-2026-7668 [HIGH] CWE-119 CVE-2026-7668: A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function
A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The exploit is publicly available and might be
nvd
CVE-2017-8338P3HIGHCVSS 7.5v6.38.52017-05-18
CVE-2017-8338 [HIGH] CWE-400 CVE-2017-8338: A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all devices will be disconnected from the router and all logs removed automatically.
nvd
CVE-2020-11881P3HIGHCVSS 7.5≥ 6.41.3, ≤ 6.46.5v7.02020-09-14
CVE-2020-11881 [HIGH] CWE-129 CVE-2020-11881: An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows a
An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated remote attacker to crash the SMB server via modified setup-request packets, aka SUP-12964.
nvd
CVE-2018-10066P3HIGHCVSS 8.1v6.41.42018-04-13
CVE-2018-10066 [HIGH] CWE-295 CVE-2018-10066: An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification
An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification allows a remote unauthenticated attacker capable of intercepting client traffic to act as a malicious OpenVPN server. This may allow the attacker to gain access to the client's internal network (for example, at site-to-site tunnels).
nvd
CVE-2026-93345P3HIGHCVSS 7.5≤ 7.24.22026-09-22
CVE-2026-93345 [HIGH] CWE-1284 CVE-2026-93345: MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labell
MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which
nvd
CVE-2025-6563P4MEDIUMCVSS 4.8PoCfixed in 7.19.22025-07-03
CVE-2025-6563 [MEDIUM] CWE-20 CVE-2025-6563: A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions be
A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victim browses to the malicious URL and logs in, the XSS executes. The POST request used to login, can also be converted to a GET request, allowing an attacker
nvd
CVE-2026-89028P3HIGHCVSS 7.5≤ 6.49.18≥ 7.0.0, ≤ 7.11.22026-09-16
CVE-2026-89028 [HIGH] CWE-122 CVE-2026-89028: MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB d
MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, caus
nvd
CVE-2019-16160P3HIGHCVSS 7.5fixed in 6.45.52020-10-07
CVE-2019-16160 [HIGH] CWE-191 CVE-2019-16160: An integer underflow in the SMB server of MikroTik RouterOS before 6.45.5 allows remote unauthentica
An integer underflow in the SMB server of MikroTik RouterOS before 6.45.5 allows remote unauthenticated attackers to crash the service.
nvd
CVE-2019-13074P3HIGHCVSS 7.5≤ 6.44.32019-07-03
CVE-2019-13074 [HIGH] CWE-770 CVE-2019-13074: A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to
A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.
nvd