The dojo blog.
Vulnerabilities explained with the commands to protect yourself, RouterOS updates to know before installing them, news and products — in English, from official sources.

RADVD Vulnerability in RouterOS
CVE-2023-32154 is a remote code execution (RCE) vulnerability in the Router Advertisement Daemon (RADVD) of MikroTik RouterOS. It affects versions 6.49.7 Stable and earlier, allowing nearby network attackers to execute code with root privileges without authentication. The fixed version has not yet been announced; you must monitor official vendor announcements.
SecurityUnauthorized access to the REST API in RouterOS
CVE-2023-41570 is an access control vulnerability in the RouterOS REST API that allows an authenticated user with low privileges to access sensitive data. It affects versions 7.1 through 7.11. Updating to version 7.12 or later resolves the issue; alternatively, you must restrict access to the REST API to trusted hosts only.
SecurityHeap corruption in RouterOS 6 WebFig
CVE-2023-30800 is a heap memory corruption flaw in the web server of RouterOS version 6. An unauthenticated remote attacker can crash the web interface by sending a malicious HTTP request. The vulnerability is fixed in stable version 6.49.10; RouterOS version 7 is not affected.
SecurityArbitrary code execution on RouterOS
CVE-2023-30799 is a privilege escalation vulnerability that allows an authenticated attacker with an admin account to obtain super-admin privileges and execute arbitrary code. It affects stable versions of RouterOS prior to 6.49.7 and long-term versions up to and including 6.48.6. Updating to a patched version is the primary measure to mitigate the risk.
SecurityDenial of Service in the RouterOS SSH Server
CVE-2020-20021 is a Denial of Service (DoS) vulnerability affecting the SSH server in MikroTik Router v6.46.3 and earlier versions. A remote attacker can cause a service interruption by exploiting a misconfigured SSH daemon. To mitigate the risk, you must update the firmware to a later version or restrict access to the SSH service to the trusted administration network only.
ProductsMikroTik CRS354-48G-4S+2Q+RM: 48-port rackmount switch
The MikroTik CRS354-48G-4S+2Q+RM is a rackmount switch with 48 Gigabit Ethernet ports, 4 SFP+ 10G ports, and 2 QSFP+ 40G ports. It is designed for high-density network environments that require fast fiber connectivity and the advanced management provided by RouterOS. It stands out for including 40G ports in a standard rack format, offering a non-blocking switching capacity of 336 Gbps.
SecurityDoS Vulnerability in bridge2 of RouterOS v6.40.5
CVE-2023-24094 is an Out-of-bounds Write vulnerability in the bridge2 component of MikroTik RouterOS v6.40.5 that allows a remote attacker to cause a Denial of Service (DoS) via malicious packets. The vulnerability is classified as HIGH with a CVSS score of 7.5. Corrective versions and specific mitigation details have not yet been disclosed in available sources.
SecurityOut-of-bounds read in SNMP on RouterOS
CVE-2022-45315 is a critical vulnerability (CVSS 9.8) that allows an authenticated attacker to execute arbitrary code via a malicious SNMP packet. It affects RouterOS versions prior to 7.6. To mitigate the risk, upgrade to a later stable version or disable the SNMP service if not required.
SecurityOut-of-bounds Read in the Hotspot Process
CVE-2022-45313 is an Out-of-bounds Read vulnerability in the hotspot process of RouterOS, allowing arbitrary code execution via a manipulated nova message. It affects RouterOS versions prior to 7.5. To mitigate the risk, you must update to a stable version later than 7.5 or disable the hotspot service if not in use.
DojoHotspot 2.0 and Passpoint with MikroTik: Interworking in the WiFi Package
Hotspot 2.0 (commercial name Passpoint, underlying standard 802.11u) allows a phone to automatically and securely connect to a public WiFi network without a login page, recognizing its own carrier or organization. In 2017, I discovered an undocumented menu in RouterOS 6; today, the WiFi package in RouterOS 7 includes an official menu, /interface wifi interworking, to be used together with a RADIUS server.
SecurityCritical vulnerability in the RouterOS web server
CVE-2017-20149 is a critical vulnerability (CVSS 9.8) in the RouterOS web server that allows an unauthenticated remote user to execute arbitrary code. It affects versions prior to 6.37.5 and 6.38.5. You must immediately update the firmware to a later version to eliminate the risk.
ProductsMikroTik ROSE Data Server (RDS): specifications and usage
The MikroTik ROSE Data Server (RDS) is an all-in-one enterprise platform that combines high-density NVMe storage, 100G networking, and container support. It is designed for business environments that need to consolidate network infrastructure, storage, and computing into a single rackmount device, reducing complexity and power consumption compared to separate solutions.
Security35 DoS vulnerabilities in RouterOS 6.44–6.48: who is at risk and which version to install
Between 2021 and 2022, 35 nearly identical CVEs were published for RouterOS 6: in each case, a system process (console, sniffer, resolver, lcdstat, and others) crashes when it receives crafted input, causing a denial of service on the router. They all have a CVSS score of 6.5 and share one common factor that significantly reduces the risk: valid credentials on the router are required. They affect versions from 6.44 to 6.48.3; the solution is to upgrade to the latest 6.49 or to RouterOS 7, and in the meantime, restrict who can log in.