Skip to content
Topic

Hardening

Securing the router: services, users, management access, vulnerabilities to close: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per Safe Mode di MikroTik: come funziona la rete di sicurezza di RouterOS
Knowledge base
Knowledge base · Safe Mode

MikroTik Safe Mode: How RouterOS’s Safety Net Works

Safe Mode is RouterOS's safety net: while it is active, the router logs every change and, if the session that made them drops, it rolls them back automatically. You enable it with Ctrl+X (or F4) in the terminal and with the Safe Mode button in WinBox. It holds up to 100 actions and does not cover commands that restart the router.

8 min read
Illustrazione per Il matcher psd di MikroTik: come RouterOS riconosce le scansioni di porteKnowledge base
Knowledge base · Port scan detection

The PSD matcher in MikroTik: how RouterOS detects port scans

The PSD matcher in the RouterOS firewall detects port scans: it adds a weight for each different port touched by the same address within a short time window, and when the total reaches the threshold, the rule triggers. Usually, it places the scanner in an address list, and another rule drops it. Place it below the rules that accept legitimate traffic, and note that it does not detect slow scans.

Illustrazione per Firewall filter MikroTik: chain input, forward, output e ordine delle regoleKnowledge base
Knowledge base · Firewall filter

MikroTik Firewall Filter: input, forward, output chains and rule order

The RouterOS firewall filter directs every packet into one of three chains: input (to the router), forward (through the router), output (from the router). In each chain, rules are read from top to bottom, and the first match with an action such as accept or drop ends the processing; if no rule matches, the packet passes. For this reason, a new rule must always be placed above the final drop, never below it.

Illustrazione per Address list del firewall MikroTik: come funzionano in RouterOS 7Knowledge base
Knowledge base · Address list

MikroTik firewall address list: how they work in RouterOS 7

An address list is a named list of addresses that firewall rules use instead of a manually written address. You add the entries yourself (static) or the firewall adds them automatically as traffic passes (dynamic, usually with an expiration). This mechanism is the basis for blacklists, port knocking, management allowlists, and domain filters.

Illustrazione per Interface list MikroTik: come funzionano e perché il firewall le preferisceKnowledge base
Knowledge base · Interface list

Interface list MikroTik: come funzionano e perché il firewall le preferisce

Una interface list è un gruppo di interfacce con un nome, per esempio WAN o LAN. Le regole del firewall, il neighbor discovery e il MAC server guardano la lista invece della singola porta: quando aggiungi una linea PPPoE, una LTE o una seconda WAN, la metti nella lista e le regole valgono subito anche per lei.

Illustrazione per CVE-2026-84411Security
CVE-2026-84411

Critical vulnerability in RouterOS web service

CVE-2026-84411 is a critical vulnerability (CVSS 9.8) in the RouterOS management web service that allows an unauthenticated attacker to execute arbitrary code as root or cause a denial of service. All RouterOS versions below 7.24 are affected. The immediate action is to update the firmware to version 7.24 or later and restrict access to the web service to trusted networks only.

Critical · 9.8
Illustrazione per CVE-2025-56566Security
CVE-2025-56566

Cleartext credentials on SPI flash

MikroTik firmware 7.19.4 stores authentication credentials and network state in cleartext on non-volatile memory. An attacker with physical access to the device can extract this data from an SPI flash dump without authenticating. No corrective versions or specific mitigations have been communicated by the vendor.

Medium · 4.6
Illustrazione per CVE-2026-89020Security
CVE-2026-89020

Stack-based buffer overflow in mtget (RouterOS)

CVE-2026-89020 is a stack-based buffer overflow vulnerability in the mtget binary of RouterOS that allows an authenticated user to crash the mtget worker process by sending a /tool fetch command with a TFTP path of 507 bytes or more. RouterOS versions prior to 7.23.4 (long-term) and 7.24.2 (stable) are affected. To protect yourself, you must update to one of the indicated fixed versions.

Medium · 4.3
Illustrazione per CVE-2026-67277Security
CVE-2026-67277

Critical vulnerability in the RouterOS btest service

CVE-2026-67277 is a high-severity vulnerability (CVSS 8.2) that allows an unauthenticated client to cause a RouterOS kernel reboot via the Bandwidth Test (btest) service. The vulnerability affects versions prior to 6.49.21, 7.23.4, and 7.24.2 and was added to the CISA KEV catalog on September 10, 2026. You must immediately update the firmware to the fixed versions or disable the btest service if it is not in use.

High · 8.2Exploited
Illustrazione per Aggiornamento di sicurezza critico per RouterOS: cosa fare subitoAdvisories
MikroTik advisory

RouterOS: security advisory and fixed versions

MikroTik has released a critical security update for RouterOS due to a recently discovered vulnerability. While most configurations are not at immediate risk, the update is strongly recommended for all users. The fixed versions include 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21 (and later).

Illustrazione per Port knocking su MikroTik: WinBox si apre solo a chi bussaDojo

Port knocking on MikroTik: WinBox opens only for those who knock

The router's management port stays closed to everyone and opens for one hour only to those who touch three ports in the correct sequence. Firewall rules for RouterOS 7, three ways to knock from Linux (knock, nc, and pure bash), and how much you can trust it.

Illustrazione per Difetto di gestione sessioni nell'API di RouterOSSecurity
CVE-2026-14227

Session Management Flaw in RouterOS API

CVE-2026-14227 is an Insufficient Session Expiration vulnerability in the RouterOS API that allows authenticated sessions to retain elevated privileges even after rights are reduced or the timeout is exceeded. It affects all RouterOS versions with the API enabled and reachable from untrusted networks. Immediate mitigation consists of disabling the API if not required or restricting access to authorized hosts only, pending a corrective release.

Medium · 4.9
Illustrazione per CVE-2026-16347Security
CVE-2026-16347

RouterOS API Vulnerability: Brute-Force Risk

CVE-2026-16347 is a high-severity vulnerability (CVSS 8.8) affecting all RouterOS versions due to the lack of effective limits on API authentication attempts. An attacker can perform a high volume of login attempts to guess administrative credentials. Immediate mitigation consists of disabling the API if not required or restricting access to authorized management hosts only, pending a corrective release.

High · 8.8