Skip to content
Security

Security

RouterOS and MikroTik device vulnerabilities, with the commands to protect yourself.

Illustrazione per CVE-2026-67277
Security High · 8.2Exploited
CVE-2026-67277

Critical vulnerability in the RouterOS btest service

CVE-2026-67277 is a high-severity vulnerability (CVSS 8.2) that allows an unauthenticated client to cause a RouterOS kernel reboot via the Bandwidth Test (btest) service. The vulnerability affects versions prior to 6.49.21, 7.23.4, and 7.24.2 and was added to the CISA KEV catalog on September 10, 2026. You must immediately update the firmware to the fixed versions or disable the btest service if it is not in use.

3 min read
Illustrazione per CVE-2026-67279Security
CVE-2026-67279

SSH Vulnerability in RouterOS: Unauthenticated Access

CVE-2026-67279 allows an unauthenticated client to open an SSH session and send exec requests, enabling the creation, overwriting, or reconstruction of files within the namespace managed by RouterOS. Versions prior to 6.49.21, 7.23.4, and 7.24.2 are affected. The vulnerability is listed in the CISA KEV catalog: you must update the firmware immediately.

Medium · 6.5Exploited
Illustrazione per Aggiornamento di sicurezza critico per RouterOS: cosa fare subitoAdvisories
MikroTik advisory

RouterOS: security advisory and fixed versions

MikroTik has released a critical security update for RouterOS due to a recently discovered vulnerability. While most configurations are not at immediate risk, the update is strongly recommended for all users. The fixed versions include 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21 (and later).

Illustrazione per Difetto di gestione sessioni nell'API di RouterOSSecurity
CVE-2026-14227

Session Management Flaw in RouterOS API

CVE-2026-14227 is an Insufficient Session Expiration vulnerability in the RouterOS API that allows authenticated sessions to retain elevated privileges even after rights are reduced or the timeout is exceeded. It affects all RouterOS versions with the API enabled and reachable from untrusted networks. Immediate mitigation consists of disabling the API if not required or restricting access to authorized hosts only, pending a corrective release.

Medium · 4.9
Illustrazione per CVE-2026-16347Security
CVE-2026-16347

RouterOS API Vulnerability: Brute-Force Risk

CVE-2026-16347 is a high-severity vulnerability (CVSS 8.8) affecting all RouterOS versions due to the lack of effective limits on API authentication attempts. An attacker can perform a high volume of login attempts to guess administrative credentials. Immediate mitigation consists of disabling the API if not required or restricting access to authorized management hosts only, pending a corrective release.

High · 8.8
Illustrazione per CVE-2026-39042Security
CVE-2026-39042

Denial of Service in libumsg.so of RouterOS

CVE-2026-39042 is an Integer Overflow or Wraparound vulnerability in the unflatten() function of the libumsg.so library that allows a remote attacker to cause a denial of service. It affects versions 7.21.x prior to v.7.21.4 and 7.22.x prior to v.7.22.2. You must update the firmware to the indicated corrective versions.

High · 7.5
Illustrazione per CVE-2025-61481Security
CVE-2025-61481

WebFig Exposed in Clear on RouterOS and SwOS

CVE-2025-61481 exposes the WebFig management interface of RouterOS v.7.14.2 and SwOS v.2.18 via unencrypted HTTP, allowing a man-in-the-middle attacker to inject JavaScript into the administrator's browser and intercept credentials. The vulnerability is classified as critical with a CVSS score of 10.0. To mitigate the risk, disable WebFig if not necessary or restrict access exclusively to the trusted management network.

Critical · 10.0
Illustrazione per CVE-2025-10948Security
CVE-2025-10948

Buffer overflow in libjson.so of RouterOS 7

CVE-2025-10948 is a buffer overflow vulnerability in the parse_json_element function of the libjson.so component, reachable via the /rest/ip/address/print REST endpoint. It affects RouterOS 7 and can be exploited remotely. Updating to versions 7.20.1 or 7.21beta2 resolves the issue.

High · 8.8
Illustrazione per CVE-2025-6563Security
CVE-2025-6563

XSS in RouterOS Hotspot

CVE-2025-6563 is a cross-site scripting (XSS) vulnerability in the RouterOS hotspot service in versions prior to 7.19.2. An attacker can inject JavaScript code via the dst parameter to execute scripts in the victim's browser upon login. To mitigate the risk, you must update to version 7.19.2 or later.

Medium · 4.8
Illustrazione per CVE-2023-47310Security
CVE-2023-47310

Bypass firewall IPv6 UDP in RouterOS 7

CVE-2023-47310 is a default configuration vulnerability in MikroTik RouterOS 7 that allows IPv6 UDP traceroute packets to bypass the firewall. It affects versions prior to 7.14. The mitigation is to update to RouterOS 7.14 or later.

Medium · 6.5
Illustrazione per CVE-2025-6443Security
CVE-2025-6443

VXLAN Vulnerability in RouterOS: CVE-2025-6443

CVE-2025-6443 is an improper access control vulnerability (CWE-284) in the VXLAN service of MikroTik RouterOS that allows a remote attacker, without authentication, to bypass access restrictions and reach internal network resources. Versions 7.15.3 and 7.16.2 are confirmed vulnerable by CVE.org, while NVD indicates all versions prior to 7.20; the exact fixed version has not yet been announced. Those using VXLAN on untrusted networks must update the firmware as soon as it becomes available and verify the service configuration.

Illustrazione per CVE-2024-54952Security
CVE-2024-54952

DoS Vulnerability in the SMB Service of RouterOS

CVE-2024-54952 is a memory corruption vulnerability in the SMB service of MikroTik RouterOS 6.40.5 that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) by making the SMB service inaccessible. The version specified as affected is 6.40.5; corrective versions have not yet been announced. To mitigate the risk, you must disable the SMB service if it is not strictly necessary or update to the next stable release when available.

High · 7.5
Illustrazione per CVE-2024-54772Security
CVE-2024-54772

Account Enumeration in Winbox on RouterOS

CVE-2024-54772 allows an attacker to identify valid usernames on a MikroTik router by analyzing differences in Winbox service response times. Affected versions include long-term 6.43.13 through 6.49.13 and stable 6.43 through 7.17.2. To mitigate the risk, upgrade to version 6.49.18 or later and restrict Winbox access to the management network.

Medium · 5.4