
Security
RouterOS and MikroTik device vulnerabilities, with the commands to protect yourself.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

CVE-2018-14847: Recovering plaintext passwords from user.dat on RouterOS v6
We reproduced the CVE-2018-14847 vulnerability on RouterOS v6, confirming that an unauthenticated attacker can read the user.dat file and recover plaintext passwords due to a weak XOR transformation. The issue is fixed in versions 6.40.8, 6.42.11, and 6.49.7, where access to the file is denied.
SecurityCritical vulnerability in RouterOS web service
CVE-2026-84411 is a critical vulnerability (CVSS 9.8) in the RouterOS management web service that allows an unauthenticated attacker to execute arbitrary code as root or cause a denial of service. All RouterOS versions below 7.24 are affected. The immediate action is to update the firmware to version 7.24 or later and restrict access to the web service to trusted networks only.
SecurityDoS on BGP in RouterOS via NLRI VPN
CVE-2026-93345 is an improper input validation vulnerability in the routing service of MikroTik RouterOS that allows an unauthenticated attacker to crash the BGP service. Versions up to 7.24.2 are affected, including the long-term release 7.23.5; the fix is only present in the development version 7.25beta4. To mitigate the risk, restrict access to the BGP service to authorized peers only and monitor the availability of a corrected stable release.
AdvisoriesRouterOS 7.23.6 and 7.24.3: LTE warning for RBSXTLTE3-7 and SXTsq
MikroTik has issued a critical warning: do not update RBSXTLTE3-7, EC25-EU&KNe, EG25-G&KNe, EC25-EU&SXTsq, and EG25-G&SXTsq devices to RouterOS versions 7.23.6 or 7.24.3. The update renders the LTE interface non-functional. If you have already updated, you must downgrade to 7.23.5 or 7.24.2 and update the modem firmware to restore connectivity.
SecurityCleartext credentials on SPI flash
MikroTik firmware 7.19.4 stores authentication credentials and network state in cleartext on non-volatile memory. An attacker with physical access to the device can extract this data from an SPI flash dump without authenticating. No corrective versions or specific mitigations have been communicated by the vendor.
SecurityOut-of-bounds Read in the SMB Daemon of RouterOS
CVE-2026-56719 is an Out-of-bounds Read vulnerability in the SMB daemon of MikroTik RouterOS. It affects versions up to 7.11.2 and 6.49.18, allowing an unauthenticated attacker to read sensitive memory via a manipulated SMB1 frame. Updating to version 7.24.0 resolves the issue; alternatively, disabling the SMB service eliminates the exposure.
SecurityHeap corruption in the SMB daemon of RouterOS
CVE-2026-89028 is a heap memory corruption vulnerability in the SMB daemon of RouterOS that allows a remote attacker to cause a denial of service. It affects versions up to 7.11.2 and 6.49.18; the fix is available in version 7.24.0. To mitigate the risk, you must update to 7.24.0 or disable the SMB service if not in use.
SecurityPath traversal in the RouterOS container package
CVE-2026-89021 is a path traversal vulnerability in the RouterOS container package that allows an authenticated attacker to write, delete, or create links to files outside the container root without starting it. It affects versions prior to 7.24.2; the fix is not planned for the 7.23.x long-term branch. If you use the container package in device-mode, update to a stable version 7.24.2 or higher, or disable the service.
SecurityStack-based buffer overflow in mtget (RouterOS)
CVE-2026-89020 is a stack-based buffer overflow vulnerability in the mtget binary of RouterOS that allows an authenticated user to crash the mtget worker process by sending a /tool fetch command with a TFTP path of 507 bytes or more. RouterOS versions prior to 7.23.4 (long-term) and 7.24.2 (stable) are affected. To protect yourself, you must update to one of the indicated fixed versions.
SecurityUnauthorized file read in WebFig
CVE-2026-67281 is an unauthenticated file read vulnerability in the WebFig service of RouterOS that allows an attacker to access restricted files, including credential databases. It affects 7.x versions lower than 7.23.4 and 7.24.2. You must update the firmware or disable remote access to WebFig.
SecurityRSA Key Verification Flaw in SSH Server
RouterOS does not compare the RSA public key exponent during SSH authentication, allowing an attacker to forge valid signatures if they know the modulus of an authorized key. This issue affects 7.x versions prior to 7.23.4 and 7.24.2. You must update the firmware or restrict access to the SSH service to trusted networks only.
SecurityFlawed RSA Signature in RouterOS: CVE-2026-67278
CVE-2026-67278 is a critical vulnerability (CVSS 9.1) that allows an attacker to forge TLS certificates and SSH authentications on MikroTik RouterOS routers. It affects 7.x versions prior to 7.23.6 and 7.24.3; releases 7.23.4 and 7.24.2 contain an incomplete fix. To protect yourself, immediately update to one of the fixed versions or disable RSA services exposed to untrusted networks.
SecurityUnauthorized command execution via SSH
CVE-2026-86060 is a critical vulnerability in the RouterOS SSH server that allows unauthenticated privilege escalation. It affects versions prior to 6.49.21, 7.23.4, and 7.24.2. It is listed in the CISA KEV catalog and must be patched immediately.