
Code execution
Remote code execution (RCE), even as root: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

Critical vulnerability in RouterOS web service
CVE-2026-84411 is a critical vulnerability (CVSS 9.8) in the RouterOS management web service that allows an unauthenticated attacker to execute arbitrary code as root or cause a denial of service. All RouterOS versions below 7.24 are affected. The immediate action is to update the firmware to version 7.24 or later and restrict access to the web service to trusted networks only.
SecurityRADVD Vulnerability in RouterOS
CVE-2023-32154 is a remote code execution (RCE) vulnerability in the Router Advertisement Daemon (RADVD) of MikroTik RouterOS. It affects versions 6.49.7 Stable and earlier, allowing nearby network attackers to execute code with root privileges without authentication. The fixed version has not yet been announced; you must monitor official vendor announcements.
SecurityArbitrary code execution on RouterOS
CVE-2023-30799 is a privilege escalation vulnerability that allows an authenticated attacker with an admin account to obtain super-admin privileges and execute arbitrary code. It affects stable versions of RouterOS prior to 6.49.7 and long-term versions up to and including 6.48.6. Updating to a patched version is the primary measure to mitigate the risk.
SecurityOut-of-bounds read in SNMP on RouterOS
CVE-2022-45315 is a critical vulnerability (CVSS 9.8) that allows an authenticated attacker to execute arbitrary code via a malicious SNMP packet. It affects RouterOS versions prior to 7.6. To mitigate the risk, upgrade to a later stable version or disable the SNMP service if not required.
SecurityOut-of-bounds Read in the Hotspot Process
CVE-2022-45313 is an Out-of-bounds Read vulnerability in the hotspot process of RouterOS, allowing arbitrary code execution via a manipulated nova message. It affects RouterOS versions prior to 7.5. To mitigate the risk, you must update to a stable version later than 7.5 or disable the hotspot service if not in use.
SecurityCritical vulnerability in the RouterOS web server
CVE-2017-20149 is a critical vulnerability (CVSS 9.8) in the RouterOS web server that allows an unauthenticated remote user to execute arbitrary code. It affects versions prior to 6.37.5 and 6.38.5. You must immediately update the firmware to a later version to eliminate the risk.
SecurityBuffer overflow in the RouterOS SCEP server
CVE-2021-41987 is a critical vulnerability (CVSS 8.1) in the RouterOS SCEP server that allows remote code execution. It affects versions 6.46.8, 6.47.9, and 6.47.10. You must update the firmware to a later version not listed as vulnerable or disable the SCEP service if not in use.
SecurityBuffer overflow in the RouterOS license update interface
CVE-2018-1156 is an Out-of-bounds Write (CWE-787) vulnerability in RouterOS versions prior to 6.40.9 and 6.42.7. A remote authenticated attacker could theoretically execute arbitrary code on the system through the license update interface. To mitigate the risk, you must update the firmware to the fixed versions.
SecurityBuffer overflow in the SMB service of RouterOS
CVE-2018-7445 is a critical vulnerability (CVSS 9.8) in the SMB service of RouterOS that allows an unauthenticated attacker to execute code. It affects all RouterOS versions prior to 6.41.3. The vulnerability is listed in the CISA KEV catalog and requires applying updates according to the vendor's instructions.