Security
RouterOS and MikroTik device vulnerabilities, with the commands to protect yourself.

Buffer overflow in the RouterOS license update interface
CVE-2018-1156 is an Out-of-bounds Write (CWE-787) vulnerability in RouterOS versions prior to 6.40.9 and 6.42.7. A remote authenticated attacker could theoretically execute arbitrary code on the system through the license update interface. To mitigate the risk, you must update the firmware to the fixed versions.
SecurityWinBox Vulnerability in RouterOS
CVE-2018-14847 is a critical vulnerability in the WinBox component of MikroTik RouterOS that allows an unauthenticated attacker to read arbitrary files and an authenticated attacker to write new ones. The vulnerability is present in RouterOS versions up to and including 6.42 and is listed in the CISA KEV catalog, indicating active exploitation. You must update the firmware to a version later than 6.42 and restrict access to the WinBox service to the management network.
SecurityDenial of Service on the FTP service in RouterOS
CVE-2018-10070 is an Uncontrolled Resource Consumption vulnerability that allows a remote unauthenticated attacker to exhaust the router's CPU and RAM by sending malicious FTP requests. The affected device is MikroTik Version 6.41.4, which reboots after approximately 10 minutes. To protect yourself, you must update the firmware to a later version or disable the FTP service if it is not strictly necessary.
SecurityBuffer overflow in the SMB service of RouterOS
CVE-2018-7445 is a critical vulnerability (CVSS 9.8) in the SMB service of RouterOS that allows an unauthenticated attacker to execute code. It affects all RouterOS versions prior to 6.41.3. The vulnerability is listed in the CISA KEV catalog and requires applying updates according to the vendor's instructions.
SecurityDenial of Service via ICMP on RouterOS v6.40.5
The CVE-2017-17538 vulnerability allows a remote attacker to cause a denial of service by sending a massive sequence of ICMP packets. It affects MikroTik devices running RouterOS version 6.40.5. To mitigate the risk, you must update the firmware to a later version or apply network filters to limit ICMP traffic.
SecurityDoS on hAP Lite 6.25 via ACK packets
CVE-2017-6444 is a denial-of-service vulnerability affecting the MikroTik Router hAP Lite device running firmware 6.25. A remote attacker can saturate the CPU by sending unsolicited TCP ACK packets, rendering the router unusable until it is rebooted. Since no fixed versions have been announced, the only certain mitigation is to isolate the device from untrusted networks or replace it.
SecuritySNMP Vulnerability in RouterOS 3.2
CVE-2008-0680 is a vulnerability that allows a remote attacker to cause the SNMP daemon to crash by sending a malicious SNMP SET request. It affects MikroTik RouterOS version 3.2 and earlier. To mitigate the risk, you must update the operating system to a later version or disable the SNMP service if it is not used.