Skip to content
Topic

API and REST

RouterOS API and REST API: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per CVE-2018-14847: Recupero password in chiaro da user.dat su RouterOS v6
Lab
Lab · CVE-2018-14847

CVE-2018-14847: Recovering plaintext passwords from user.dat on RouterOS v6

We reproduced the CVE-2018-14847 vulnerability on RouterOS v6, confirming that an unauthenticated attacker can read the user.dat file and recover plaintext passwords due to a weak XOR transformation. The issue is fixed in versions 6.40.8, 6.42.11, and 6.49.7, where access to the file is denied.

2 min read
Illustrazione per Difetto di gestione sessioni nell'API di RouterOSSecurity
CVE-2026-14227

Session Management Flaw in RouterOS API

CVE-2026-14227 is an Insufficient Session Expiration vulnerability in the RouterOS API that allows authenticated sessions to retain elevated privileges even after rights are reduced or the timeout is exceeded. It affects all RouterOS versions with the API enabled and reachable from untrusted networks. Immediate mitigation consists of disabling the API if not required or restricting access to authorized hosts only, pending a corrective release.

Medium · 4.9
Illustrazione per CVE-2026-16347Security
CVE-2026-16347

RouterOS API Vulnerability: Brute-Force Risk

CVE-2026-16347 is a high-severity vulnerability (CVSS 8.8) affecting all RouterOS versions due to the lack of effective limits on API authentication attempts. An attacker can perform a high volume of login attempts to guess administrative credentials. Immediate mitigation consists of disabling the API if not required or restricting access to authorized management hosts only, pending a corrective release.

High · 8.8
Illustrazione per CVE-2025-10948Security
CVE-2025-10948

Buffer overflow in libjson.so of RouterOS 7

CVE-2025-10948 is a buffer overflow vulnerability in the parse_json_element function of the libjson.so component, reachable via the /rest/ip/address/print REST endpoint. It affects RouterOS 7 and can be exploited remotely. Updating to versions 7.20.1 or 7.21beta2 resolves the issue.

High · 8.8
Illustrazione per CVE-2023-41570Security
CVE-2023-41570

Unauthorized access to the REST API in RouterOS

CVE-2023-41570 is an access control vulnerability in the RouterOS REST API that allows an authenticated user with low privileges to access sensitive data. It affects versions 7.1 through 7.11. Updating to version 7.12 or later resolves the issue; alternatively, you must restrict access to the REST API to trusted hosts only.

Medium · 5.3