Skip to content
Topic

Hardening

Securing the router: services, users, management access, vulnerabilities to close: all dojo articles on this topic.

Illustrazione per CVE-2026-39042
Security High · 7.5
CVE-2026-39042

Denial of Service in libumsg.so of RouterOS

CVE-2026-39042 is an Integer Overflow or Wraparound vulnerability in the unflatten() function of the libumsg.so library that allows a remote attacker to cause a denial of service. It affects versions 7.21.x prior to v.7.21.4 and 7.22.x prior to v.7.22.2. You must update the firmware to the indicated corrective versions.

2 min read
Illustrazione per Hardening di base di un router MikroTik con RouterOS 7Dojo
Howto · Security

Basic hardening of a MikroTik router with RouterOS 7

A MikroTik freshly reset with no-defaults=yes has no firewall: it is fine on the bench for learning, but it should never be put on the network like that. Before installing it, you need seven hardening steps: update RouterOS, replace the admin user, disable unused services and restrict the others to authorized addresses, close service ports on external interfaces, a minimal firewall that blocks everything coming from the internet, and a VPN for remote management.

Illustrazione per CVE-2025-61481Security
CVE-2025-61481

WebFig Exposed in Clear on RouterOS and SwOS

CVE-2025-61481 exposes the WebFig management interface of RouterOS v.7.14.2 and SwOS v.2.18 via unencrypted HTTP, allowing a man-in-the-middle attacker to inject JavaScript into the administrator's browser and intercept credentials. The vulnerability is classified as critical with a CVSS score of 10.0. To mitigate the risk, disable WebFig if not necessary or restrict access exclusively to the trusted management network.

Critical · 10.0
Illustrazione per CVE-2024-54952Security
CVE-2024-54952

DoS Vulnerability in the SMB Service of RouterOS

CVE-2024-54952 is a memory corruption vulnerability in the SMB service of MikroTik RouterOS 6.40.5 that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) by making the SMB service inaccessible. The version specified as affected is 6.40.5; corrective versions have not yet been announced. To mitigate the risk, you must disable the SMB service if it is not strictly necessary or update to the next stable release when available.

High · 7.5
Illustrazione per CVE-2023-41570Security
CVE-2023-41570

Unauthorized access to the REST API in RouterOS

CVE-2023-41570 is an access control vulnerability in the RouterOS REST API that allows an authenticated user with low privileges to access sensitive data. It affects versions 7.1 through 7.11. Updating to version 7.12 or later resolves the issue; alternatively, you must restrict access to the REST API to trusted hosts only.

Medium · 5.3
Illustrazione per CVE-2023-30800Security
CVE-2023-30800

Heap corruption in RouterOS 6 WebFig

CVE-2023-30800 is a heap memory corruption flaw in the web server of RouterOS version 6. An unauthenticated remote attacker can crash the web interface by sending a malicious HTTP request. The vulnerability is fixed in stable version 6.49.10; RouterOS version 7 is not affected.

High · 7.5
Illustrazione per CVE-2023-30799Security
CVE-2023-30799

Arbitrary code execution on RouterOS

CVE-2023-30799 is a privilege escalation vulnerability that allows an authenticated attacker with an admin account to obtain super-admin privileges and execute arbitrary code. It affects stable versions of RouterOS prior to 6.49.7 and long-term versions up to and including 6.48.6. Updating to a patched version is the primary measure to mitigate the risk.

High · 7.2
Illustrazione per 35 vulnerabilità DoS in RouterOS 6.44–6.48: chi è a rischio e quale versione installareSecurity
35 CVEs · RouterOS 6.44–6.48

35 DoS vulnerabilities in RouterOS 6.44–6.48: who is at risk and which version to install

Between 2021 and 2022, 35 nearly identical CVEs were published for RouterOS 6: in each case, a system process (console, sniffer, resolver, lcdstat, and others) crashes when it receives crafted input, causing a denial of service on the router. They all have a CVSS score of 6.5 and share one common factor that significantly reduces the risk: valid credentials on the router are required. They affect versions from 6.44 to 6.48.3; the solution is to upgrade to the latest 6.49 or to RouterOS 7, and in the meantime, restrict who can log in.

Medium · 6.5
Illustrazione per CVE-2020-22845Security
CVE-2020-22845

Buffer overflow in the FTP service of RouterOS 6.47

CVE-2020-22845 is a buffer overflow in the FTP service of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service via malicious FTP requests. The vulnerability has HIGH severity (CVSS 7.5) and specifically affects version 6.47. To mitigate the risk, you must update to a later version or disable the FTP service if not strictly necessary.

High · 7.5
Illustrazione per CVE-2021-27221Security
CVE-2021-27221

Arbitrary File Write via FTP in RouterOS

CVE-2021-27221 allows a remote authenticated user with an FTP policy to create or overwrite arbitrary .rsc files using the /export command. This flaw affects RouterOS 6.47.9, where the vendor considers this behavior intentional due to how user policies work. To mitigate the risk, you must disable the cleartext FTP service or ensure that only trusted users with appropriate policies can access it.

High · 8.1
Illustrazione per CVE-2021-3014Security
CVE-2021-3014

Reflected XSS in the Hotspot login page

CVE-2021-3014 is a reflected Cross-Site Scripting (XSS) vulnerability in the Hotspot service login page in MikroTik RouterOS. It affects RouterOS versions published up to January 4, 2021. To mitigate the risk, you must update the firmware to a later version or disable access to the Hotspot login page from untrusted networks.

Medium · 6.1
Illustrazione per CVE-2020-11881Security
CVE-2020-11881

SMB server crash in RouterOS

CVE-2020-11881 is an array index validation error in the RouterOS SMB server that allows a remote unauthenticated attacker to cause a service crash. It affects versions 6.41.3 through 6.46.5 and 7.x versions up to 7.0 Beta5. Immediate mitigation is to disable the SMB server if not strictly necessary, as the stable fixed version is not specified in the available data.

High · 7.5
Illustrazione per CVE-2020-10364Security
CVE-2020-10364

Denial of Service in the SSH daemon

CVE-2020-10364 is a high-severity vulnerability that allows a remote attacker to cause a denial of service (DoS) on the router, generating excessive CPU activity and potential reboots. It affects systems with the SSH daemon active and reachable from untrusted networks. The primary mitigation is to restrict access to the SSH service to the administration network only or disable it if not required.

High · 7.5