
API and REST
RouterOS API and REST API: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

CVE-2018-14847: Recovering plaintext passwords from user.dat on RouterOS v6
We reproduced the CVE-2018-14847 vulnerability on RouterOS v6, confirming that an unauthenticated attacker can read the user.dat file and recover plaintext passwords due to a weak XOR transformation. The issue is fixed in versions 6.40.8, 6.42.11, and 6.49.7, where access to the file is denied.
SecuritySession Management Flaw in RouterOS API
CVE-2026-14227 is an Insufficient Session Expiration vulnerability in the RouterOS API that allows authenticated sessions to retain elevated privileges even after rights are reduced or the timeout is exceeded. It affects all RouterOS versions with the API enabled and reachable from untrusted networks. Immediate mitigation consists of disabling the API if not required or restricting access to authorized hosts only, pending a corrective release.
SecurityRouterOS API Vulnerability: Brute-Force Risk
CVE-2026-16347 is a high-severity vulnerability (CVSS 8.8) affecting all RouterOS versions due to the lack of effective limits on API authentication attempts. An attacker can perform a high volume of login attempts to guess administrative credentials. Immediate mitigation consists of disabling the API if not required or restricting access to authorized management hosts only, pending a corrective release.
SecurityBuffer overflow in libjson.so of RouterOS 7
CVE-2025-10948 is a buffer overflow vulnerability in the parse_json_element function of the libjson.so component, reachable via the /rest/ip/address/print REST endpoint. It affects RouterOS 7 and can be exploited remotely. Updating to versions 7.20.1 or 7.21beta2 resolves the issue.
SecurityUnauthorized access to the REST API in RouterOS
CVE-2023-41570 is an access control vulnerability in the RouterOS REST API that allows an authenticated user with low privileges to access sensitive data. It affects versions 7.1 through 7.11. Updating to version 7.12 or later resolves the issue; alternatively, you must restrict access to the REST API to trusted hosts only.