Skip to content

The dojo blog.

Vulnerabilities explained with the commands to protect yourself, RouterOS updates to know before installing them, news and products — in English, from official sources.

Illustrazione del ATL 5G R16
Products
Product · LTE/5G

MikroTik ATL 5G R16: external 5G antenna with eSIM

The MikroTik ATL 5G R16 is an external device for 5G, LTE, and 3G mobile connectivity, designed for rooftop or outdoor installations. It features native eSIM integration with MikroTik Connectivity support, high-gain directional antennas, and IP66 certification, making it suitable for rural, urban, and IoT scenarios where signal stability is critical.

3 min read
Illustrazione per CVE-2019-13955Security
CVE-2019-13955

Stack exhaustion in RouterOS WebFig

CVE-2019-13955 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server by sending malicious HTTP requests. It affects RouterOS versions prior to 6.44.5 on the long-term release branch. To mitigate the risk, upgrade to a later version or disable the WebFig service if not required.

Illustrazione per CVE-2019-13954Security
CVE-2019-13954

Memory exhaustion in the RouterOS HTTP server

CVE-2019-13954 is a vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server by sending malicious HTTP requests, potentially causing a system reboot. It affects RouterOS versions prior to 6.44.5. To protect yourself, you must update to a later version or disable the web service if not in use.

Illustrazione per CVE-2025-42611Security
CVE-2025-42611

Certificate Validation Vulnerability in RouterOS

CVE-2025-42611 is a certificate validation vulnerability that may allow authentication bypass in services such as OpenVPN, CAPsMAN, and Dot1X. It affects RouterOS versions up to 7.20.x. The fixed version has not yet been announced; as of the article date, the vulnerability is not known to be actively exploited.

Medium · 6.5
Illustrazione per CVE-2019-13074Security
CVE-2019-13074

Memory exhaustion in the RouterOS FTP daemon

CVE-2019-13074 is a vulnerability in the RouterOS FTP daemon that allows a remote attacker to exhaust available memory, causing the device to reboot. It affects versions up to and including 6.44.3. To mitigate the risk, disable the FTP service or upgrade to a later version, if available.

Illustrazione per CVE-2026-7668Security
CVE-2026-7668

Out-of-bounds read in SCEP Endpoint

CVE-2026-7668 is an out-of-bounds read vulnerability in the SCEP Endpoint component of RouterOS 6.49.8, exploitable remotely without authentication. It affects only version 6.49.8; the vendor recommends upgrading to the latest available v6.x or 7.x version. It is not known to be actively exploited and is not included in the CISA KEV catalog.

High · 7.3
Illustrazione per CVE-2019-3943Security
CVE-2019-3943

Directory traversal in RouterOS via Winbox and HTTP

CVE-2019-3943 is a directory traversal vulnerability that allows an authenticated user to read and write files outside the /rw/disk sandbox directory via the HTTP or Winbox interfaces. It affects Stable versions 6.43.12 and earlier, Long-term versions 6.42.12 and earlier, and Testing versions 6.44beta75 and earlier. You must update to a version later than those indicated or restrict access to the affected interfaces from untrusted networks.

High · 8.1
Illustrazione per Come nascondere i router MikroTik della tua rete al tracerouteDojo
Howto · Routing

How to hide your MikroTik routers from traceroute

A traceroute launched by a client shows each router in your network, along with their addresses. By using a mangle rule that increments the TTL (action=change-ttl new-ttl=increment:1), every MikroTik router becomes invisible to traceroute, because the packet passes through it without "consuming" a hop. The rule must be limited to client traffic and applied carefully to avoid complicating troubleshooting.

Illustrazione per CVE-2019-3924Security
CVE-2019-3924

Interception vulnerability in RouterOS

CVE-2019-3924 is an interception vulnerability that allows a remote unauthenticated attacker to issue user-defined network requests to WAN and LAN clients, enabling firewall bypass or network scanning. Affected versions are long-term 6.42.11 and earlier, and stable 6.43.11 and earlier. To protect yourself, you must upgrade to a version later than those indicated.

High · 7.5
Illustrazione del CRS317-1G-16S+RMProducts
Product · Switch

MikroTik CRS317-1G-16S+RM: 10GbE Managed Switch with RouterOS or SwOS

The MikroTik CRS317-1G-16S+RM is a rackmount managed switch with 16 SFP+ ports and one copper Gigabit Ethernet port, designed for high-performance 10GbE connectivity. It stands out for the ability to choose between RouterOS and SwOS via dual boot, offering flexibility between advanced routing features and simplified switch management. It is designed for high-temperature environments thanks to passive cooling with automatic fans.

Illustrazione per CVE-2018-1159Security
CVE-2018-1159

Memory vulnerability in the RouterOS HTTP server

CVE-2018-1159 is a memory corruption vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server. Versions prior to 6.40.9 and 6.42.7 are affected. To protect yourself, you must upgrade to a later version or restrict access to the web management service.

Illustrazione per CVE-2018-1158Security
CVE-2018-1158

Stack exhaustion in the RouterOS HTTP server

CVE-2018-1158 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server through recursive JSON parsing. It affects versions prior to 6.40.9 and 6.42.7. To mitigate the risk, upgrade to a later version or restrict access to the web management service to the administration network only.

Illustrazione per CVE-2018-1157Security
CVE-2018-1157

Memory exhaustion in the RouterOS HTTP server

CVE-2018-1157 is a vulnerability that allows an authenticated attacker to crash the HTTP server and, in some cases, reboot the system. It affects RouterOS versions prior to 6.40.9 and 6.42.7. To protect yourself, you must update to a later version or disable the web service if not in use.