Skip to content
Security

Security

RouterOS and MikroTik device vulnerabilities, with the commands to protect yourself.

Illustrazione per Buffer overflow nel server SMB di RouterOS
Security High · 7.5
CVE-2020-22844

Buffer overflow in the SMB server of RouterOS

CVE-2020-22844 is a buffer overflow in the SMB server of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service through malicious SMB requests. The vulnerability specifically affects version 6.47 and is not known to be actively exploited. To mitigate the risk, you must update the firmware or disable the SMB service if it is not in use.

2 min read
Illustrazione per CVE-2021-27221Security
CVE-2021-27221

Arbitrary File Write via FTP in RouterOS

CVE-2021-27221 allows a remote authenticated user with an FTP policy to create or overwrite arbitrary .rsc files using the /export command. This flaw affects RouterOS 6.47.9, where the vendor considers this behavior intentional due to how user policies work. To mitigate the risk, you must disable the cleartext FTP service or ensure that only trusted users with appropriate policies can access it.

High · 8.1
Illustrazione per CVE-2021-3014Security
CVE-2021-3014

Reflected XSS in the Hotspot login page

CVE-2021-3014 is a reflected Cross-Site Scripting (XSS) vulnerability in the Hotspot service login page in MikroTik RouterOS. It affects RouterOS versions published up to January 4, 2021. To mitigate the risk, you must update the firmware to a later version or disable access to the Hotspot login page from untrusted networks.

Medium · 6.1
Illustrazione per CVE-2019-16160Security
CVE-2019-16160

Integer underflow in the RouterOS SMB server

CVE-2019-16160 is an integer underflow in the RouterOS SMB server that allows an unauthenticated remote attacker to crash the service. RouterOS versions prior to 6.45.5 are affected. To mitigate the risk, upgrade to a later version or disable the SMB service if not required.

High · 7.5
Illustrazione per CVE-2020-11881Security
CVE-2020-11881

SMB server crash in RouterOS

CVE-2020-11881 is an array index validation error in the RouterOS SMB server that allows a remote unauthenticated attacker to cause a service crash. It affects versions 6.41.3 through 6.46.5 and 7.x versions up to 7.0 Beta5. Immediate mitigation is to disable the SMB server if not strictly necessary, as the stable fixed version is not specified in the available data.

High · 7.5
Illustrazione per CVE-2020-5721Security
CVE-2020-5721

Plaintext password in the WinBox configuration file

WinBox 3.22 and earlier versions save the user password in unencrypted text in the configuration file if the "Keep Password" option is enabled and no Master Password is set. Since these are the default settings, an attacker with access to the file can recover the credentials to access the router. You must update WinBox to a later version or disable the password saving option.

Medium · 5.5
Illustrazione per CVE-2020-10364Security
CVE-2020-10364

Denial of Service in the SSH daemon

CVE-2020-10364 is a high-severity vulnerability that allows a remote attacker to cause a denial of service (DoS) on the router, generating excessive CPU activity and potential reboots. It affects systems with the SSH daemon active and reachable from untrusted networks. The primary mitigation is to restrict access to the SSH service to the administration network only or disable it if not required.

High · 7.5
Illustrazione per CVE-2018-5951Security
CVE-2018-5951

Reboot risk from IPv6 packet on RouterOS

CVE-2018-5951 is an availability vulnerability that allows a remote attacker to cause an immediate reboot of a MikroTik RouterOS router. The attack exploits the sending of a specific IPv6 packet with IP protocol 97 (EoIPv6). Since the description states that all RouterOS versions supporting EoIPv6 are vulnerable, it is crucial to verify if this service is active and reachable from untrusted networks.

High · 7.5
Illustrazione per CVE-2020-5720Security
CVE-2020-5720

Path traversal vulnerability in WinBox

CVE-2020-5720 is a path traversal vulnerability in WinBox, the graphical client for managing MikroTik routers. It affects all WinBox versions prior to 3.21 and allows the creation of arbitrary files if the client connects to a malicious endpoint or suffers a man-in-the-middle attack. To mitigate the risk, you must update WinBox to version 3.21 or higher and restrict access to the service only from the trusted administration network.

Medium · 5.9
Illustrazione per CVE-2019-3981Security
CVE-2019-3981

Winbox Vulnerability: Man-in-the-Middle Attack

CVE-2019-3981 is a vulnerability in MikroTik Winbox 3.20 and earlier that allows an attacker positioned between the client and the router to perform an authentication downgrade and retrieve the username and MD5-hashed password. The risk arises when Winbox is reachable from untrusted networks. To mitigate the risk, you must update Winbox to a version later than 3.20 and restrict access to the service to the administration network only.

Low · 3.7
Illustrazione per CVE-2019-3979Security
CVE-2019-3979

DNS cache poisoning vulnerability in RouterOS

CVE-2019-3979 is a high-risk vulnerability that allows a malicious DNS server to poison the router's DNS cache by adding unsolicited A records. It affects RouterOS versions 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier. To mitigate the risk, you must update the firmware or block incoming DNS traffic from the untrusted network.

High · 7.5
Illustrazione per CVE-2019-3978Security
CVE-2019-3978

DNS Cache Poisoning Vulnerability in RouterOS

CVE-2019-3978 allows unauthenticated remote attackers to generate DNS queries toward arbitrary servers, potentially poisoning the router's DNS cache. RouterOS 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier, are affected. You must update the firmware to a later version or block access to the DNS service from untrusted networks.

High · 7.5
Illustrazione per CVE-2019-3977Security
CVE-2019-3977

RouterOS autoupgrade vulnerability

CVE-2019-3977 allows a remote attacker to force the router to download and install an older version of RouterOS via the autoupgrade function, potentially resetting system credentials. Versions 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier, are affected. You must disable the autoupgrade function or update the firmware to a later version not listed as vulnerable.

High · 7.5