cbcvebase.

Mikrotik Routeros vulnerabilities

99 known vulnerabilities affecting mikrotik/routeros.

Total CVEs
99
CISA KEV
5
actively exploited
Public exploits
16
Exploited in wild
10
Severity breakdown
CRITICAL8HIGH35MEDIUM55LOW1

Vulnerabilities

Page 5 of 5
CVE-2020-20215P4MEDIUMCVSS 6.5v6.44.62021-07-07
CVE-2020-20215 [MEDIUM] CWE-787 CVE-2020-20215: Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nov Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.
nvd
CVE-2020-20220P4MEDIUMCVSS 6.5fixed in 6.472021-05-18
CVE-2020-20220 [MEDIUM] CWE-119 CVE-2020-20220: Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/b Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
nvd
CVE-2021-36613P4MEDIUMCVSS 6.5fixed in 6.48.22022-05-11
CVE-2021-36613 [MEDIUM] CWE-476 CVE-2021-36613: Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp pro Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
nvd
CVE-2020-20253P4MEDIUMCVSS 6.5fixed in 6.472021-05-18
CVE-2020-20253 [MEDIUM] CWE-369 CVE-2020-20253: Mikrotik RouterOs before 6.47 (stable tree) suffers from a divison by zero vulnerability in the /nov Mikrotik RouterOs before 6.47 (stable tree) suffers from a divison by zero vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service due to a divide by zero error.
nvd
CVE-2020-20231P4MEDIUMCVSS 6.5≥ 6.44.6, ≤ 6.48.32021-07-14
CVE-2020-20231 [MEDIUM] CWE-476 CVE-2020-20231: Mikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in th Mikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in the /nova/bin/detnet process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
nvd
CVE-2020-20230P4MEDIUMCVSS 6.5fixed in 6.472021-07-19
CVE-2020-20230 [MEDIUM] CWE-400 CVE-2020-20230: Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd p Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.
nvd
CVE-2020-20248P4MEDIUMCVSS 6.5v6.472021-07-19
CVE-2020-20248 [MEDIUM] CWE-400 CVE-2020-20248: Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtes Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.
nvd
CVE-2020-20252P4MEDIUMCVSS 6.5fixed in 6.472021-07-13
CVE-2020-20252 [MEDIUM] CWE-476 CVE-2020-20252: Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the / Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
nvd
CVE-2020-20216P4MEDIUMCVSS 6.5v6.44.62021-07-07
CVE-2020-20216 [MEDIUM] CWE-476 CVE-2020-20216: Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nov Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/graphing process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
nvd
CVE-2022-36522P4MEDIUMCVSS 6.5≤ 6.48.32022-08-26
CVE-2022-36522 [MEDIUM] CWE-617 CVE-2022-36522: Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the compo Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
nvd
CVE-2020-20247P4MEDIUMCVSS 6.5fixed in 6.46.52021-05-03
CVE-2020-20247 [MEDIUM] CWE-787 CVE-2020-20247: Mikrotik RouterOs before 6.46.5 (stable tree) suffers from a memory corruption vulnerability in the Mikrotik RouterOs before 6.46.5 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable.
nvd
CVE-2023-41570P4MEDIUMCVSS 5.3≥ 7.1, < 7.122023-11-14
CVE-2023-41570 [MEDIUM] CWE-284 CVE-2023-41570: MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in plac MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
nvd
CVE-2015-2350P4MEDIUMCVSS 6.8≤ 5.02015-03-19
CVE-2015-2350 [MEDIUM] CWE-352 CVE-2015-2350: Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote a Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request in the status page to /cfg.
nvd
CVE-2017-6297P4MEDIUMCVSS 5.9v6.37.4v6.83.32017-02-27
CVE-2017-6297 [MEDIUM] CWE-311 CVE-2017-6297: The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption aft The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.
nvd
CVE-2024-54772P4MEDIUMCVSS 5.4≥ 6.43, < 6.49.18≥ 6.43.13, ≤ 6.49.13+1 more2025-02-11
CVE-2024-54772 [MEDIUM] CWE-208 CVE-2024-54772: An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 throug An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate fo
nvd
CVE-2026-14227P4MEDIUMCVSS 4.9vAll versions2026-07-30
CVE-2026-14227 [MEDIUM] CWE-613 CVE-2026-14227: An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may contin
nvd
CVE-2026-89020P4MEDIUMCVSS 4.3fixed in 7.23.4≥ 7.24.0, < 7.24.22026-09-14
CVE-2026-89020 [MEDIUM] CWE-121 CVE-2026-89020: MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overfl MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to the /tool fetch command; the first write outside the 528-byte buffer occ
nvd
CVE-2021-3014P4MEDIUMCVSS 6.1≤ 2021-01-042021-01-04
CVE-2021-3014 [MEDIUM] CWE-79 CVE-2021-3014: In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via t In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.
nvd
CVE-2019-3981P4LOWCVSS 3.7fixed in 6.432020-01-14
CVE-2019-3981 [LOW] CWE-300 CVE-2019-3981: MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can d MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.
nvd
Mikrotik Routeros vulnerabilities | cvebase