Why one article for 35 CVEs?

Because they tell the same story 35 times. They are the result of a fuzzing campaign on the internal processes of RouterOS 6: for each one, a way to crash it was found (invalid memory access, null pointer, division by zero, failed assertion, CPU consumption) and each was assigned a CVE code. Writing 35 separate articles would not help anyone: here you find the complete table and what to do, all in one place.

Who is at risk?

The key point is in the official description of almost all of them: “an authenticated remote attacker”. To exploit them, you must already be logged in to the router. In practice, they are only dangerous if:

  • someone who should not have access has a user account on the router (a former collaborator, a client with read-only access, a shared password);
  • the credentials are weak or default, or exposed on the internet via WinBox, SSH, API, or WebFig;
  • the router acts as a shared platform (for example, providing read-only data access to third parties for monitoring).

An external attacker without credentials cannot use them. And the damage is a service disruption, not data theft or router control: the process hangs, RouterOS restarts it, or, in the worst cases, the router reboots.

Which processes and which versions?

The version indicated is the one reported in the CVE: for some it is “6.44.6 is vulnerable”, for others “prior to 6.47”.

Process What it does CVE Reported version
console RouterOS terminal CVE-2020-20211, CVE-2020-20212 6.44.5 long-term
net basic network CVE-2020-20213 6.44.5 long-term
btest Bandwidth Test CVE-2020-20214 6.44.6 long-term
diskd disk management CVE-2020-20215, CVE-2020-20227 6.44.6 long-term, 6.47 stable
graphing traffic and resource graphs CVE-2020-20216 6.44.6 long-term
route routing table CVE-2020-20217 before 6.47
traceroute traceroute CVE-2020-20218, CVE-2020-20247 6.44.6 long-term, before 6.46.5
igmp-proxy IGMP proxy (multicast) CVE-2020-20219 6.44.6 long-term
bfd BFD (link failure detection) CVE-2020-20220 before 6.47
cerm certificates CVE-2020-20221 before 6.44.6
sniffer packet sniffer CVE-2020-20222, CVE-2020-20236, CVE-2020-20237 6.44.6 long-term, 6.46.3
user user management CVE-2020-20225 before 6.47
sshd SSH server CVE-2020-20230 before 6.47
detnet Internet network detection CVE-2020-20231 up to 6.48.3
log system log CVE-2020-20245 6.46.3
mactel MAC Telnet CVE-2020-20246 6.46.3
memtest memory test CVE-2020-20248 before 6.47
resolver DNS CVE-2020-20249, CVE-2020-20267 before 6.47
lcdstat LCD display CVE-2020-20250, CVE-2020-20252, CVE-2020-20253, CVE-2020-20254 before 6.47
ipsec IPsec CVE-2020-20262 before 6.47
netwatch Netwatch CVE-2020-20264, CVE-2022-36522 before 6.47, up to 6.48.3
wireless wireless (legacy package) CVE-2020-20265 before 6.47
dot1x 802.1X CVE-2020-20266 before 6.47
ptp Precision Time Protocol CVE-2021-36613 before 6.48.2
tr069-client TR-069 client CVE-2021-36614 before 6.48.2

What should I do?

Three things, in order of importance.

Step 1: update

The CVEs indicate that versions up to 6.48.3 are vulnerable. If the router is still on RouterOS 6, upgrade the device to the latest 6.49 long-term; if the hardware allows it, consider migrating to RouterOS 7. Check the version with:

/system resource print
/system package update print

If the router is on the network:

/system package update set channel=long-term
/system package update check-for-updates
/system package update install

If you cannot reach the internet, or if you need a specific version, you can find all packages in the RouterOS Archive: select the architecture and version, and you will get direct links to download.mikrotik.com, with the manual update procedure explained in RouterOS channels.

Step 2: control who can get in

Since a login is required, the most effective defense is to reduce the number of users and access points:

/user print
/user active print
/ip service print

Remove users that are no longer needed, change shared passwords, and limit management services using Available From to administration networks only. The full procedure is in Basic hardening of a MikroTik router.

Step 3: turn off what you do not use

Many of the processes in the table run only if the feature is active or the package is installed (sniffer, btest, IGMP proxy, TR-069, PTP, lcdstat on devices with a display). Fewer active services mean a smaller attack surface, for these CVEs and for future ones. For example, the Bandwidth Test server:

/tool bandwidth-server set enabled=no

Frequently asked questions

Are these 35 RouterOS CVEs dangerous?

They have medium severity (CVSS 6.5): they only allow blocking a process or restarting the router, and only for those who already have valid credentials. They do not allow stealing data or taking control of the device.

Which RouterOS versions are affected?

The CVEs indicate RouterOS 6 versions from 6.44 to 6.48.3. The solution is to update to the latest 6.49 long-term version or switch to RouterOS 7.

Do you need to be authenticated to exploit them?

Yes. The official descriptions mention an authenticated remote attacker: without a valid user on the router, these vulnerabilities cannot be exploited.

How do I protect myself if I cannot update immediately?

By reducing who can access the router: remove unnecessary users, use strong passwords, and limit management services using Available From to administration networks only.