Skip to main content

Vendor/product archive

mikrotik / routeros CVEs

Beta · best-effort

82 CVEs tagged to mikrotik / routeros5 Critical, 27 High, 49 Medium, 1 Low, 0 Unrated.

CVE-2025-6443

Published Jun 25, 2025

Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikr…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54952

Published May 29, 2025

MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54772

Published Feb 11, 2025

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32154

Published May 3, 2024

Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected install…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41570

Published Nov 14, 2023

MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30800

Published Sep 7, 2023

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30799

Published Jul 19, 2023

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges fro…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2020-20021

Published Jul 12, 2023

An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24094

Published Mar 27, 2023

An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45315

Published Dec 5, 2022

Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated attackers to execute arbitrary co…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45313

Published Dec 5, 2022

Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a cr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-20149

Published Oct 15, 2022

The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-36522

Published Aug 26, 2022

Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34960

Published Aug 25, 2022

The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allow…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-36614

Published May 11, 2022

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An authenticated remote attacker can cause a Denial of Service (…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36613

Published May 11, 2022

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL poin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41987

Published Mar 16, 2022

In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the s…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-22845

Published Feb 28, 2022

A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted FTP requests.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-22844

Published Feb 28, 2022

A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-20262

Published Jul 21, 2021

Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An authenticated remote attacker can…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20221

Published Jul 21, 2021

Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm process. An authenticated remote attacker ca…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20219

Published Jul 21, 2021

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process. An authenticated remote attacker can cause a Denial o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20249

Published Jul 19, 2021

Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenticated remote attacker can caus…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20248

Published Jul 19, 2021

Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can cause a Denial of Service due t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-20230

Published Jul 19, 2021

Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can cause a Denial of Service due to o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 82 CVEsPage 1 of 4