Skip to content
Security

Security

RouterOS and MikroTik device vulnerabilities, with the commands to protect yourself.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per CVE-2018-14847: Recupero password in chiaro da user.dat su RouterOS v6
Lab
Lab · CVE-2018-14847

CVE-2018-14847: Recovering plaintext passwords from user.dat on RouterOS v6

We reproduced the CVE-2018-14847 vulnerability on RouterOS v6, confirming that an unauthenticated attacker can read the user.dat file and recover plaintext passwords due to a weak XOR transformation. The issue is fixed in versions 6.40.8, 6.42.11, and 6.49.7, where access to the file is denied.

2 min read
Illustrazione per CVE-2026-84411Security
CVE-2026-84411

Critical vulnerability in RouterOS web service

CVE-2026-84411 is a critical vulnerability (CVSS 9.8) in the RouterOS management web service that allows an unauthenticated attacker to execute arbitrary code as root or cause a denial of service. All RouterOS versions below 7.24 are affected. The immediate action is to update the firmware to version 7.24 or later and restrict access to the web service to trusted networks only.

Critical · 9.8
Illustrazione per CVE-2026-93345Security
CVE-2026-93345

DoS on BGP in RouterOS via NLRI VPN

CVE-2026-93345 is an improper input validation vulnerability in the routing service of MikroTik RouterOS that allows an unauthenticated attacker to crash the BGP service. Versions up to 7.24.2 are affected, including the long-term release 7.23.5; the fix is only present in the development version 7.25beta4. To mitigate the risk, restrict access to the BGP service to authorized peers only and monitor the availability of a corrected stable release.

High · 7.5
Illustrazione per RouterOS 7.23.6 e 7.24.3: avviso LTE su RBSXTLTE3-7 e SXTsqAdvisories
MikroTik warning

RouterOS 7.23.6 and 7.24.3: LTE warning for RBSXTLTE3-7 and SXTsq

MikroTik has issued a critical warning: do not update RBSXTLTE3-7, EC25-EU&KNe, EG25-G&KNe, EC25-EU&SXTsq, and EG25-G&SXTsq devices to RouterOS versions 7.23.6 or 7.24.3. The update renders the LTE interface non-functional. If you have already updated, you must downgrade to 7.23.5 or 7.24.2 and update the modem firmware to restore connectivity.

Illustrazione per CVE-2025-56566Security
CVE-2025-56566

Cleartext credentials on SPI flash

MikroTik firmware 7.19.4 stores authentication credentials and network state in cleartext on non-volatile memory. An attacker with physical access to the device can extract this data from an SPI flash dump without authenticating. No corrective versions or specific mitigations have been communicated by the vendor.

Medium · 4.6
Illustrazione per CVE-2026-56719Security
CVE-2026-56719

Out-of-bounds Read in the SMB Daemon of RouterOS

CVE-2026-56719 is an Out-of-bounds Read vulnerability in the SMB daemon of MikroTik RouterOS. It affects versions up to 7.11.2 and 6.49.18, allowing an unauthenticated attacker to read sensitive memory via a manipulated SMB1 frame. Updating to version 7.24.0 resolves the issue; alternatively, disabling the SMB service eliminates the exposure.

Medium · 6.5
Illustrazione per CVE-2026-89028Security
CVE-2026-89028

Heap corruption in the SMB daemon of RouterOS

CVE-2026-89028 is a heap memory corruption vulnerability in the SMB daemon of RouterOS that allows a remote attacker to cause a denial of service. It affects versions up to 7.11.2 and 6.49.18; the fix is available in version 7.24.0. To mitigate the risk, you must update to 7.24.0 or disable the SMB service if not in use.

High · 7.5
Illustrazione per CVE-2026-89021Security
CVE-2026-89021

Path traversal in the RouterOS container package

CVE-2026-89021 is a path traversal vulnerability in the RouterOS container package that allows an authenticated attacker to write, delete, or create links to files outside the container root without starting it. It affects versions prior to 7.24.2; the fix is not planned for the 7.23.x long-term branch. If you use the container package in device-mode, update to a stable version 7.24.2 or higher, or disable the service.

Medium · 6.9
Illustrazione per CVE-2026-89020Security
CVE-2026-89020

Stack-based buffer overflow in mtget (RouterOS)

CVE-2026-89020 is a stack-based buffer overflow vulnerability in the mtget binary of RouterOS that allows an authenticated user to crash the mtget worker process by sending a /tool fetch command with a TFTP path of 507 bytes or more. RouterOS versions prior to 7.23.4 (long-term) and 7.24.2 (stable) are affected. To protect yourself, you must update to one of the indicated fixed versions.

Medium · 4.3
Illustrazione per CVE-2026-67281Security
CVE-2026-67281

Unauthorized file read in WebFig

CVE-2026-67281 is an unauthenticated file read vulnerability in the WebFig service of RouterOS that allows an attacker to access restricted files, including credential databases. It affects 7.x versions lower than 7.23.4 and 7.24.2. You must update the firmware or disable remote access to WebFig.

High · 7.5
Illustrazione per CVE-2026-67276Security
CVE-2026-67276

RSA Key Verification Flaw in SSH Server

RouterOS does not compare the RSA public key exponent during SSH authentication, allowing an attacker to forge valid signatures if they know the modulus of an authorized key. This issue affects 7.x versions prior to 7.23.4 and 7.24.2. You must update the firmware or restrict access to the SSH service to trusted networks only.

High · 8.1
Illustrazione per CVE-2026-67278Security
CVE-2026-67278

Flawed RSA Signature in RouterOS: CVE-2026-67278

CVE-2026-67278 is a critical vulnerability (CVSS 9.1) that allows an attacker to forge TLS certificates and SSH authentications on MikroTik RouterOS routers. It affects 7.x versions prior to 7.23.6 and 7.24.3; releases 7.23.4 and 7.24.2 contain an incomplete fix. To protect yourself, immediately update to one of the fixed versions or disable RSA services exposed to untrusted networks.

Critical · 9.1
Illustrazione per CVE-2026-86060Security
CVE-2026-86060

Unauthorized command execution via SSH

CVE-2026-86060 is a critical vulnerability in the RouterOS SSH server that allows unauthenticated privilege escalation. It affects versions prior to 6.49.21, 7.23.4, and 7.24.2. It is listed in the CISA KEV catalog and must be patched immediately.

Critical · 9.8Exploited