Skip to content

The dojo blog.

Vulnerabilities explained with the commands to protect yourself, RouterOS updates to know before installing them, news and products — in English, from official sources.

Illustrazione per Vulnerabilità RADVD in RouterOS
Security
CVE-2023-32154

RADVD Vulnerability in RouterOS

CVE-2023-32154 is a remote code execution (RCE) vulnerability in the Router Advertisement Daemon (RADVD) of MikroTik RouterOS. It affects versions 6.49.7 Stable and earlier, allowing nearby network attackers to execute code with root privileges without authentication. The fixed version has not yet been announced; you must monitor official vendor announcements.

2 min read
Illustrazione per CVE-2023-41570Security
CVE-2023-41570

Unauthorized access to the REST API in RouterOS

CVE-2023-41570 is an access control vulnerability in the RouterOS REST API that allows an authenticated user with low privileges to access sensitive data. It affects versions 7.1 through 7.11. Updating to version 7.12 or later resolves the issue; alternatively, you must restrict access to the REST API to trusted hosts only.

Medium · 5.3
Illustrazione per CVE-2023-30800Security
CVE-2023-30800

Heap corruption in RouterOS 6 WebFig

CVE-2023-30800 is a heap memory corruption flaw in the web server of RouterOS version 6. An unauthenticated remote attacker can crash the web interface by sending a malicious HTTP request. The vulnerability is fixed in stable version 6.49.10; RouterOS version 7 is not affected.

High · 7.5
Illustrazione per CVE-2023-30799Security
CVE-2023-30799

Arbitrary code execution on RouterOS

CVE-2023-30799 is a privilege escalation vulnerability that allows an authenticated attacker with an admin account to obtain super-admin privileges and execute arbitrary code. It affects stable versions of RouterOS prior to 6.49.7 and long-term versions up to and including 6.48.6. Updating to a patched version is the primary measure to mitigate the risk.

High · 7.2
Illustrazione per Denial of Service nel server SSH di RouterOSSecurity
CVE-2020-20021

Denial of Service in the RouterOS SSH Server

CVE-2020-20021 is a Denial of Service (DoS) vulnerability affecting the SSH server in MikroTik Router v6.46.3 and earlier versions. A remote attacker can cause a service interruption by exploiting a misconfigured SSH daemon. To mitigate the risk, you must update the firmware to a later version or restrict access to the SSH service to the trusted administration network only.

High · 7.5
Illustrazione del CRS354-48G-4S+2Q+RMProducts
Product · Switch

MikroTik CRS354-48G-4S+2Q+RM: 48-port rackmount switch

The MikroTik CRS354-48G-4S+2Q+RM is a rackmount switch with 48 Gigabit Ethernet ports, 4 SFP+ 10G ports, and 2 QSFP+ 40G ports. It is designed for high-density network environments that require fast fiber connectivity and the advanced management provided by RouterOS. It stands out for including 40G ports in a standard rack format, offering a non-blocking switching capacity of 336 Gbps.

Illustrazione per Vulnerabilità DoS in bridge2 di RouterOS v6.40.5Security
CVE-2023-24094

DoS Vulnerability in bridge2 of RouterOS v6.40.5

CVE-2023-24094 is an Out-of-bounds Write vulnerability in the bridge2 component of MikroTik RouterOS v6.40.5 that allows a remote attacker to cause a Denial of Service (DoS) via malicious packets. The vulnerability is classified as HIGH with a CVSS score of 7.5. Corrective versions and specific mitigation details have not yet been disclosed in available sources.

High · 7.5
Illustrazione per CVE-2022-45315Security
CVE-2022-45315

Out-of-bounds read in SNMP on RouterOS

CVE-2022-45315 is a critical vulnerability (CVSS 9.8) that allows an authenticated attacker to execute arbitrary code via a malicious SNMP packet. It affects RouterOS versions prior to 7.6. To mitigate the risk, upgrade to a later stable version or disable the SNMP service if not required.

Critical · 9.8
Illustrazione per CVE-2022-45313Security
CVE-2022-45313

Out-of-bounds Read in the Hotspot Process

CVE-2022-45313 is an Out-of-bounds Read vulnerability in the hotspot process of RouterOS, allowing arbitrary code execution via a manipulated nova message. It affects RouterOS versions prior to 7.5. To mitigate the risk, you must update to a stable version later than 7.5 or disable the hotspot service if not in use.

High · 8.8
Illustrazione per Hotspot 2.0 e Passpoint con MikroTik: l'interworking nel pacchetto wifiDojo
Howto · WiFi

Hotspot 2.0 and Passpoint with MikroTik: Interworking in the WiFi Package

Hotspot 2.0 (commercial name Passpoint, underlying standard 802.11u) allows a phone to automatically and securely connect to a public WiFi network without a login page, recognizing its own carrier or organization. In 2017, I discovered an undocumented menu in RouterOS 6; today, the WiFi package in RouterOS 7 includes an official menu, /interface wifi interworking, to be used together with a RADIUS server.

Illustrazione per CVE-2017-20149Security
CVE-2017-20149

Critical vulnerability in the RouterOS web server

CVE-2017-20149 is a critical vulnerability (CVSS 9.8) in the RouterOS web server that allows an unauthenticated remote user to execute arbitrary code. It affects versions prior to 6.37.5 and 6.38.5. You must immediately update the firmware to a later version to eliminate the risk.

Critical · 9.8
Illustrazione del ROSE Data server (RDS)Products
Product · Router

MikroTik ROSE Data Server (RDS): specifications and usage

The MikroTik ROSE Data Server (RDS) is an all-in-one enterprise platform that combines high-density NVMe storage, 100G networking, and container support. It is designed for business environments that need to consolidate network infrastructure, storage, and computing into a single rackmount device, reducing complexity and power consumption compared to separate solutions.

Illustrazione per 35 vulnerabilità DoS in RouterOS 6.44–6.48: chi è a rischio e quale versione installareSecurity
35 CVEs · RouterOS 6.44–6.48

35 DoS vulnerabilities in RouterOS 6.44–6.48: who is at risk and which version to install

Between 2021 and 2022, 35 nearly identical CVEs were published for RouterOS 6: in each case, a system process (console, sniffer, resolver, lcdstat, and others) crashes when it receives crafted input, causing a denial of service on the router. They all have a CVSS score of 6.5 and share one common factor that significantly reduces the risk: valid credentials on the router are required. They affect versions from 6.44 to 6.48.3; the solution is to upgrade to the latest 6.49 or to RouterOS 7, and in the meantime, restrict who can log in.

Medium · 6.5