MikroTik RouterOS

Three-year CVE watchlist for MikroTik and RouterOS vulnerabilities relevant to routing, VPN and edge network security.

Dedicated CVE watchlist

MikroTik RouterOS

Three-year CVE watchlist for MikroTik and RouterOS vulnerabilities relevant to routing, VPN and edge network security.

Server administration
CategorySwitch between product-focused CVE watchlists.
Showsorted by operational relevance for DataHouse infrastructure
CVE-2026-67276CVSS 9.2SSH

CVE-2026-67276

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacke...

Updated: 2026-09-09
CVE-2026-48695CVSS 8.1Web

CVE-2026-48695: fastnetmon vulnerability

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenatin...

Updated: 2026-07-21
CVE-2023-30800CVSS 7.5MikroTik

CVE-2023-30800: routeros vulnerability

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is imm...

Updated: 2026-06-17
CVE-2023-30799CVSS 9.1MikroTik

CVE-2023-30799: routeros vulnerability

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse...

Updated: 2026-06-17
CVE-2025-61481CVSS 10.0MikroTik

CVE-2025-61481

An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials.

Updated: 2026-06-17
CVE-2020-20021CVSS 7.5SSH

CVE-2020-20021: routeros vulnerability

An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.

Updated: 2026-07-09
CVE-2024-54772CVSS 5.4MikroTik

CVE-2024-54772: routeros vulnerability

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts ...

Updated: 2026-06-17
CVE-2025-10948CVSS 7.4MikroTik

CVE-2025-10948

A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads to buffer overflow. The attack is possible to be carried out remotely....

Updated: 2026-06-17
CVE-2025-6563CVSS 4.8MikroTik

CVE-2025-6563

A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victim browses to the malicious URL and logs in, the XSS execut...

Updated: 2026-06-17
CVE-2023-32154CVSS 7.5MikroTik

CVE-2023-32154: routeros vulnerability

Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vu...

Updated: 2026-06-17
CVE-2024-27686CVSS 7.5MikroTik

CVE-2024-27686

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

Updated: 2026-06-17
CVE-2026-39042CVSS 7.5MikroTik

CVE-2026-39042

An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.

Updated: 2026-07-15
CVE-2026-89028CVSS 8.2MikroTik

CVE-2026-89028

MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker c...

Updated: 2026-09-17
CVE-2024-54952CVSS 7.5MikroTik

CVE-2024-54952: routeros vulnerability

MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Serv...

Updated: 2026-06-17
CVE-2025-6443CVSS 7.2MikroTik

CVE-2025-6443: routeros vulnerability

Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability. ...

Updated: 2026-06-17
CVE-2023-41570CVSS 5.3MikroTik

CVE-2023-41570: routeros vulnerability

MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.

Updated: 2026-06-17
CVE-2026-67281CVSS 8.7MikroTik

CVE-2026-67281

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so th...

Updated: 2026-09-08
CVE-2026-67279CVSS 6.9SSH

CVE-2026-67279

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches t...

Updated: 2026-09-08
CVE-2026-56719CVSS 6.3MikroTik

CVE-2026-56719

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionS...

Updated: 2026-09-16
CVE-2026-7668CVSS 5.5MikroTik

CVE-2026-7668

A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-o...

Updated: 2026-06-17
CVE-2026-89020CVSS 5.3MikroTik

CVE-2026-89020

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of...

Updated: 2026-09-16
CVE-2026-14227CVSS 6.9MikroTik

CVE-2026-14227

An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑g...

Updated: 2026-09-08
CVE-2026-16347CVSS 8.7MikroTik

CVE-2026-16347

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated...

Updated: 2026-07-30
CVE-2026-89021CVSS 6.9Containers

CVE-2026-89021

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitr...

Updated: 2026-09-16
CVE-2023-47310CVSS 6.5Firewall

CVE-2023-47310

A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets.

Updated: 2026-07-05
CVE-2023-54126Linux

CVE-2023-54126

In the Linux kernel, the following vulnerability has been resolved: crypto: safexcel - Cleanup ring IRQ workqueues on load failure A failure loading the safexcel driver results in the following warning on boot, because the IRQ affinity has not been correc...

Updated: 2026-06-17
CVE-2024-38861CVSS 4.9Mail

CVE-2024-38861: mikrotik vulnerability

Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traffic. This issue affects MikroTik: from 2.0.0 through 2.5.5, from 0.4a_mk through 2.0a.

Updated: 2026-06-17
CVE-2025-42611CVSS 6.5VPN

CVE-2025-42611

RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerability lies in shar...

Updated: 2026-06-17
CVE-2026-67278CVSS 6.3SSH

CVE-2026-67278

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an ...

Updated: 2026-09-17
CVE-2025-56566MikroTik

CVE-2025-56566

MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authenticating to the d...

Updated: 2026-09-16

Security newsletter

Get new CVE alerts before they become an incident

We send selected infrastructure threats in English, with practical notes for DataHouse environments.

  • DataHouse: server administration and secure cloud
  • Hostilla.pl: hosting and mail services
  • SecDNS.pl: free DNS security layer