← Back

Mikrotik

mikrotik

87 CVEs • 31 products

Products (31)

Click to collapse
Toggle
Routeros
routeros
Winbox
winbox
Routerboard
routerboard
Router
router
Ccr1016 12g
ccr1016-12g
Hex
hex
Hex Lite
hex_lite
Hex Poe
hex_poe
Hex Poe Lite
hex_poe_lite
Hex S
hex_s
Powerbox
powerbox
Powerbox Pro
powerbox_pro
Rb1100ahx4
rb1100ahx4
Rb2011il In
rb2011il-in
Rb2011il Rm
rb2011il-rm
Rb2011ils In
rb2011ils-in
Rb2011uias In
rb2011uias-in
Rb2011uias Rm
rb2011uias-rm
Rb3011uias Rm
rb3011uias-rm
Rb4011igs+rm
rb4011igs+rm

CVEs (87)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mikrotik
1Routeros
Aug 18, 2025
Jun 25, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS. Authentication is not requ...Show more
Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of remote IP addresses when processing VXLAN traffic. The issue results from the lack of validation of the remote IP address against configured values prior to allowing ingress traffic into the internal network. An attacker can leverage this vulnerability to gain access to internal network resources. Was ZDI-CAN-26415.Show less
1Mikrotik
1Routeros
Jun 30, 2025
May 29, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference....Show more
MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Service (DoS), rendering the SMB service unavailable.Show less
1Mikrotik
1Routeros
Jun 30, 2025
Feb 11, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in respo...Show more
An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.Show less
1Mikrotik
1Routeros
Jun 30, 2025
May 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. Authenticati...Show more
Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Router Advertisement Daemon. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-19797.Show less
1Mikrotik
1Routeros
Nov 21, 2024
Nov 14, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
1Mikrotik
1Routeros
Nov 21, 2025
Sep 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result,...Show more
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.Show less
1Mikrotik
1Routeros
Nov 21, 2025
Jul 19, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or H...Show more
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.Show less
1Mikrotik
1Routeros
Nov 21, 2024
Jul 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.
1Mikrotik
1Routeros
Feb 19, 2025
Mar 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets.
1Mikrotik
1Routeros
Apr 9, 2026
Dec 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated attackers to execute arbitrary code via a crafted packet.
1Mikrotik
1Routeros
Apr 24, 2025
Dec 5, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message.
1Mikrotik
1Routeros
May 14, 2025
Oct 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP r...Show more
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later.Show less
1Mikrotik
1Routeros
Nov 21, 2024
Aug 26, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cra...Show more
Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.Show less
1Mikrotik
1Routeros
Nov 21, 2024
Aug 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary fil...Show more
The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.Show less
1Mikrotik
1Routeros
Nov 21, 2024
May 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
1Mikrotik
1Routeros
Nov 21, 2024
May 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
1Mikrotik
1Routeros
Nov 21, 2024
Mar 16, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects Route...Show more
In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects RouterOS 6.46.8, 6.47.9, and 6.47.10.Show less
1Mikrotik
1Routeros
Nov 21, 2024
Feb 28, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted FTP requests.
1Mikrotik
1Routeros
Nov 21, 2024
Feb 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.
1Mikrotik
1Routeros
Nov 21, 2024
Jul 21, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An authenticated remote attacker can cause a Denial of Service due to an asser...Show more
Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.Show less