Why one article for 35 CVEs?
Because they tell the same story 35 times. They are the result of a fuzzing campaign on the internal processes of RouterOS 6: for each one, a way to crash it was found (invalid memory access, null pointer, division by zero, failed assertion, CPU consumption) and each was assigned a CVE code. Writing 35 separate articles would not help anyone: here you find the complete table and what to do, all in one place.
Who is at risk?
The key point is in the official description of almost all of them: “an authenticated remote attacker”. To exploit them, you must already be logged in to the router. In practice, they are only dangerous if:
- someone who should not have access has a user account on the router (a former collaborator, a client with read-only access, a shared password);
- the credentials are weak or default, or exposed on the internet via WinBox, SSH, API, or WebFig;
- the router acts as a shared platform (for example, providing read-only data access to third parties for monitoring).
An external attacker without credentials cannot use them. And the damage is a service disruption, not data theft or router control: the process hangs, RouterOS restarts it, or, in the worst cases, the router reboots.
Which processes and which versions?
The version indicated is the one reported in the CVE: for some it is “6.44.6 is vulnerable”, for others “prior to 6.47”.
| Process | What it does | CVE | Reported version |
|---|---|---|---|
console |
RouterOS terminal | CVE-2020-20211, CVE-2020-20212 | 6.44.5 long-term |
net |
basic network | CVE-2020-20213 | 6.44.5 long-term |
btest |
Bandwidth Test | CVE-2020-20214 | 6.44.6 long-term |
diskd |
disk management | CVE-2020-20215, CVE-2020-20227 | 6.44.6 long-term, 6.47 stable |
graphing |
traffic and resource graphs | CVE-2020-20216 | 6.44.6 long-term |
route |
routing table | CVE-2020-20217 | before 6.47 |
traceroute |
traceroute | CVE-2020-20218, CVE-2020-20247 | 6.44.6 long-term, before 6.46.5 |
igmp-proxy |
IGMP proxy (multicast) | CVE-2020-20219 | 6.44.6 long-term |
bfd |
BFD (link failure detection) | CVE-2020-20220 | before 6.47 |
cerm |
certificates | CVE-2020-20221 | before 6.44.6 |
sniffer |
packet sniffer | CVE-2020-20222, CVE-2020-20236, CVE-2020-20237 | 6.44.6 long-term, 6.46.3 |
user |
user management | CVE-2020-20225 | before 6.47 |
sshd |
SSH server | CVE-2020-20230 | before 6.47 |
detnet |
Internet network detection | CVE-2020-20231 | up to 6.48.3 |
log |
system log | CVE-2020-20245 | 6.46.3 |
mactel |
MAC Telnet | CVE-2020-20246 | 6.46.3 |
memtest |
memory test | CVE-2020-20248 | before 6.47 |
resolver |
DNS | CVE-2020-20249, CVE-2020-20267 | before 6.47 |
lcdstat |
LCD display | CVE-2020-20250, CVE-2020-20252, CVE-2020-20253, CVE-2020-20254 | before 6.47 |
ipsec |
IPsec | CVE-2020-20262 | before 6.47 |
netwatch |
Netwatch | CVE-2020-20264, CVE-2022-36522 | before 6.47, up to 6.48.3 |
wireless |
wireless (legacy package) | CVE-2020-20265 | before 6.47 |
dot1x |
802.1X | CVE-2020-20266 | before 6.47 |
ptp |
Precision Time Protocol | CVE-2021-36613 | before 6.48.2 |
tr069-client |
TR-069 client | CVE-2021-36614 | before 6.48.2 |
What should I do?
Three things, in order of importance.
Step 1: update
The CVEs indicate that versions up to 6.48.3 are vulnerable. If the router is still on RouterOS 6, upgrade the device to the latest 6.49 long-term; if the hardware allows it, consider migrating to RouterOS 7. Check the version with:
/system resource print
/system package update print
If the router is on the network:
/system package update set channel=long-term
/system package update check-for-updates
/system package update install
If you cannot reach the internet, or if you need a specific version, you can find all packages in the RouterOS Archive: select the architecture and version, and you will get direct links to download.mikrotik.com, with the manual update procedure explained in RouterOS channels.
Step 2: control who can get in
Since a login is required, the most effective defense is to reduce the number of users and access points:
/user print
/user active print
/ip service print
Remove users that are no longer needed, change shared passwords, and limit management services using Available From to administration networks only. The full procedure is in Basic hardening of a MikroTik router.
Step 3: turn off what you do not use
Many of the processes in the table run only if the feature is active or the package is installed (sniffer, btest, IGMP proxy, TR-069, PTP, lcdstat on devices with a display). Fewer active services mean a smaller attack surface, for these CVEs and for future ones. For example, the Bandwidth Test server:
/tool bandwidth-server set enabled=no
Frequently asked questions
Are these 35 RouterOS CVEs dangerous?
They have medium severity (CVSS 6.5): they only allow blocking a process or restarting the router, and only for those who already have valid credentials. They do not allow stealing data or taking control of the device.
Which RouterOS versions are affected?
The CVEs indicate RouterOS 6 versions from 6.44 to 6.48.3. The solution is to update to the latest 6.49 long-term version or switch to RouterOS 7.
Do you need to be authenticated to exploit them?
Yes. The official descriptions mention an authenticated remote attacker: without a valid user on the router, these vulnerabilities cannot be exploited.
How do I protect myself if I cannot update immediately?
By reducing who can access the router: remove unnecessary users, use strong passwords, and limit management services using Available From to administration networks only.



