Skip to content
Security

Security

RouterOS and MikroTik device vulnerabilities, with the commands to protect yourself.

Illustrazione per CVE-2019-3976
Security High · 8.8
CVE-2019-3976

Arbitrary directory creation in RouterOS

CVE-2019-3976 allows an authenticated user to create an arbitrary directory and enable the developer shell by installing a malicious package. It affects RouterOS 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier. The administrator must update the firmware to a version later than those indicated to eliminate the risk.

2 min read
Illustrazione per Denial of Service nel servizio SMB di RouterOS x86Security
CVE-2024-27686

Denial of Service in the SMB service of RouterOS x86

CVE-2024-27686 allows a remote attacker to crash the device by sending malicious data packets to the SMB service on TCP port 445. This vulnerability affects RouterOS versions 6.40.5 through 6.49.10 for the x86 architecture. To mitigate the risk, you must disable the SMB service or upgrade to a 7.x version, as the fix is only available in the 7 series.

High · 7.5
Illustrazione per CVE-2019-15055Security
CVE-2019-15055

Path Traversal Vulnerability in RouterOS (CVE-2019-15055)

CVE-2019-15055 is a path traversal vulnerability that allows authenticated users to delete arbitrary files on MikroTik RouterOS systems. The attack can lead to the reset of credential storage, permitting access to the management interface as an administrator without authentication. You must update the firmware to a version later than the vulnerable releases indicated in the description.

Illustrazione per CVE-2019-13955Security
CVE-2019-13955

Stack exhaustion in RouterOS WebFig

CVE-2019-13955 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server by sending malicious HTTP requests. It affects RouterOS versions prior to 6.44.5 on the long-term release branch. To mitigate the risk, upgrade to a later version or disable the WebFig service if not required.

Illustrazione per CVE-2019-13954Security
CVE-2019-13954

Memory exhaustion in the RouterOS HTTP server

CVE-2019-13954 is a vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server by sending malicious HTTP requests, potentially causing a system reboot. It affects RouterOS versions prior to 6.44.5. To protect yourself, you must update to a later version or disable the web service if not in use.

Illustrazione per CVE-2025-42611Security
CVE-2025-42611

Certificate Validation Vulnerability in RouterOS

CVE-2025-42611 is a certificate validation vulnerability that may allow authentication bypass in services such as OpenVPN, CAPsMAN, and Dot1X. It affects RouterOS versions up to 7.20.x. The fixed version has not yet been announced; as of the article date, the vulnerability is not known to be actively exploited.

Medium · 6.5
Illustrazione per CVE-2019-13074Security
CVE-2019-13074

Memory exhaustion in the RouterOS FTP daemon

CVE-2019-13074 is a vulnerability in the RouterOS FTP daemon that allows a remote attacker to exhaust available memory, causing the device to reboot. It affects versions up to and including 6.44.3. To mitigate the risk, disable the FTP service or upgrade to a later version, if available.

Illustrazione per CVE-2026-7668Security
CVE-2026-7668

Out-of-bounds read in SCEP Endpoint

CVE-2026-7668 is an out-of-bounds read vulnerability in the SCEP Endpoint component of RouterOS 6.49.8, exploitable remotely without authentication. It affects only version 6.49.8; the vendor recommends upgrading to the latest available v6.x or 7.x version. It is not known to be actively exploited and is not included in the CISA KEV catalog.

High · 7.3
Illustrazione per CVE-2019-3943Security
CVE-2019-3943

Directory traversal in RouterOS via Winbox and HTTP

CVE-2019-3943 is a directory traversal vulnerability that allows an authenticated user to read and write files outside the /rw/disk sandbox directory via the HTTP or Winbox interfaces. It affects Stable versions 6.43.12 and earlier, Long-term versions 6.42.12 and earlier, and Testing versions 6.44beta75 and earlier. You must update to a version later than those indicated or restrict access to the affected interfaces from untrusted networks.

High · 8.1
Illustrazione per CVE-2019-3924Security
CVE-2019-3924

Interception vulnerability in RouterOS

CVE-2019-3924 is an interception vulnerability that allows a remote unauthenticated attacker to issue user-defined network requests to WAN and LAN clients, enabling firewall bypass or network scanning. Affected versions are long-term 6.42.11 and earlier, and stable 6.43.11 and earlier. To protect yourself, you must upgrade to a version later than those indicated.

High · 7.5
Illustrazione per CVE-2018-1159Security
CVE-2018-1159

Memory vulnerability in the RouterOS HTTP server

CVE-2018-1159 is a memory corruption vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server. Versions prior to 6.40.9 and 6.42.7 are affected. To protect yourself, you must upgrade to a later version or restrict access to the web management service.

Illustrazione per CVE-2018-1158Security
CVE-2018-1158

Stack exhaustion in the RouterOS HTTP server

CVE-2018-1158 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server through recursive JSON parsing. It affects versions prior to 6.40.9 and 6.42.7. To mitigate the risk, upgrade to a later version or restrict access to the web management service to the administration network only.

Illustrazione per CVE-2018-1157Security
CVE-2018-1157

Memory exhaustion in the RouterOS HTTP server

CVE-2018-1157 is a vulnerability that allows an authenticated attacker to crash the HTTP server and, in some cases, reboot the system. It affects RouterOS versions prior to 6.40.9 and 6.42.7. To protect yourself, you must update to a later version or disable the web service if not in use.