
Denial of Service
Vulnerabilities that block or restart the router or one of its services: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

The PSD matcher in MikroTik: how RouterOS detects port scans
The PSD matcher in the RouterOS firewall detects port scans: it adds a weight for each different port touched by the same address within a short time window, and when the total reaches the threshold, the rule triggers. Usually, it places the scanner in an address list, and another rule drops it. Place it below the rules that accept legitimate traffic, and note that it does not detect slow scans.
SecurityCritical vulnerability in RouterOS web service
CVE-2026-84411 is a critical vulnerability (CVSS 9.8) in the RouterOS management web service that allows an unauthenticated attacker to execute arbitrary code as root or cause a denial of service. All RouterOS versions below 7.24 are affected. The immediate action is to update the firmware to version 7.24 or later and restrict access to the web service to trusted networks only.
SecurityDoS on BGP in RouterOS via NLRI VPN
CVE-2026-93345 is an improper input validation vulnerability in the routing service of MikroTik RouterOS that allows an unauthenticated attacker to crash the BGP service. Versions up to 7.24.2 are affected, including the long-term release 7.23.5; the fix is only present in the development version 7.25beta4. To mitigate the risk, restrict access to the BGP service to authorized peers only and monitor the availability of a corrected stable release.
SecurityHeap corruption in the SMB daemon of RouterOS
CVE-2026-89028 is a heap memory corruption vulnerability in the SMB daemon of RouterOS that allows a remote attacker to cause a denial of service. It affects versions up to 7.11.2 and 6.49.18; the fix is available in version 7.24.0. To mitigate the risk, you must update to 7.24.0 or disable the SMB service if not in use.
SecurityStack-based buffer overflow in mtget (RouterOS)
CVE-2026-89020 is a stack-based buffer overflow vulnerability in the mtget binary of RouterOS that allows an authenticated user to crash the mtget worker process by sending a /tool fetch command with a TFTP path of 507 bytes or more. RouterOS versions prior to 7.23.4 (long-term) and 7.24.2 (stable) are affected. To protect yourself, you must update to one of the indicated fixed versions.
SecurityCritical vulnerability in the RouterOS btest service
CVE-2026-67277 is a high-severity vulnerability (CVSS 8.2) that allows an unauthenticated client to cause a RouterOS kernel reboot via the Bandwidth Test (btest) service. The vulnerability affects versions prior to 6.49.21, 7.23.4, and 7.24.2 and was added to the CISA KEV catalog on September 10, 2026. You must immediately update the firmware to the fixed versions or disable the btest service if it is not in use.
SecurityDenial of Service in libumsg.so of RouterOS
CVE-2026-39042 is an Integer Overflow or Wraparound vulnerability in the unflatten() function of the libumsg.so library that allows a remote attacker to cause a denial of service. It affects versions 7.21.x prior to v.7.21.4 and 7.22.x prior to v.7.22.2. You must update the firmware to the indicated corrective versions.
SecurityBuffer overflow in libjson.so of RouterOS 7
CVE-2025-10948 is a buffer overflow vulnerability in the parse_json_element function of the libjson.so component, reachable via the /rest/ip/address/print REST endpoint. It affects RouterOS 7 and can be exploited remotely. Updating to versions 7.20.1 or 7.21beta2 resolves the issue.
SecurityDoS Vulnerability in the SMB Service of RouterOS
CVE-2024-54952 is a memory corruption vulnerability in the SMB service of MikroTik RouterOS 6.40.5 that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) by making the SMB service inaccessible. The version specified as affected is 6.40.5; corrective versions have not yet been announced. To mitigate the risk, you must disable the SMB service if it is not strictly necessary or update to the next stable release when available.
SecurityHeap corruption in RouterOS 6 WebFig
CVE-2023-30800 is a heap memory corruption flaw in the web server of RouterOS version 6. An unauthenticated remote attacker can crash the web interface by sending a malicious HTTP request. The vulnerability is fixed in stable version 6.49.10; RouterOS version 7 is not affected.
SecurityDenial of Service in the RouterOS SSH Server
CVE-2020-20021 is a Denial of Service (DoS) vulnerability affecting the SSH server in MikroTik Router v6.46.3 and earlier versions. A remote attacker can cause a service interruption by exploiting a misconfigured SSH daemon. To mitigate the risk, you must update the firmware to a later version or restrict access to the SSH service to the trusted administration network only.
SecurityDoS Vulnerability in bridge2 of RouterOS v6.40.5
CVE-2023-24094 is an Out-of-bounds Write vulnerability in the bridge2 component of MikroTik RouterOS v6.40.5 that allows a remote attacker to cause a Denial of Service (DoS) via malicious packets. The vulnerability is classified as HIGH with a CVSS score of 7.5. Corrective versions and specific mitigation details have not yet been disclosed in available sources.
Security35 DoS vulnerabilities in RouterOS 6.44–6.48: who is at risk and which version to install
Between 2021 and 2022, 35 nearly identical CVEs were published for RouterOS 6: in each case, a system process (console, sniffer, resolver, lcdstat, and others) crashes when it receives crafted input, causing a denial of service on the router. They all have a CVSS score of 6.5 and share one common factor that significantly reduces the risk: valid credentials on the router are required. They affect versions from 6.44 to 6.48.3; the solution is to upgrade to the latest 6.49 or to RouterOS 7, and in the meantime, restrict who can log in.