Hardening
Securing the router: services, users, management access, vulnerabilities to close: all dojo articles on this topic.

Winbox Vulnerability: Man-in-the-Middle Attack
CVE-2019-3981 is a vulnerability in MikroTik Winbox 3.20 and earlier that allows an attacker positioned between the client and the router to perform an authentication downgrade and retrieve the username and MD5-hashed password. The risk arises when Winbox is reachable from untrusted networks. To mitigate the risk, you must update Winbox to a version later than 3.20 and restrict access to the service to the administration network only.
SecurityDNS cache poisoning vulnerability in RouterOS
CVE-2019-3979 is a high-risk vulnerability that allows a malicious DNS server to poison the router's DNS cache by adding unsolicited A records. It affects RouterOS versions 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier. To mitigate the risk, you must update the firmware or block incoming DNS traffic from the untrusted network.
SecurityDNS Cache Poisoning Vulnerability in RouterOS
CVE-2019-3978 allows unauthenticated remote attackers to generate DNS queries toward arbitrary servers, potentially poisoning the router's DNS cache. RouterOS 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier, are affected. You must update the firmware to a later version or block access to the DNS service from untrusted networks.
SecurityRouterOS autoupgrade vulnerability
CVE-2019-3977 allows a remote attacker to force the router to download and install an older version of RouterOS via the autoupgrade function, potentially resetting system credentials. Versions 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier, are affected. You must disable the autoupgrade function or update the firmware to a later version not listed as vulnerable.
SecurityArbitrary directory creation in RouterOS
CVE-2019-3976 allows an authenticated user to create an arbitrary directory and enable the developer shell by installing a malicious package. It affects RouterOS 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier. The administrator must update the firmware to a version later than those indicated to eliminate the risk.
SecurityDenial of Service in the SMB service of RouterOS x86
CVE-2024-27686 allows a remote attacker to crash the device by sending malicious data packets to the SMB service on TCP port 445. This vulnerability affects RouterOS versions 6.40.5 through 6.49.10 for the x86 architecture. To mitigate the risk, you must disable the SMB service or upgrade to a 7.x version, as the fix is only available in the 7 series.
SecurityMemory exhaustion in the RouterOS FTP daemon
CVE-2019-13074 is a vulnerability in the RouterOS FTP daemon that allows a remote attacker to exhaust available memory, causing the device to reboot. It affects versions up to and including 6.44.3. To mitigate the risk, disable the FTP service or upgrade to a later version, if available.
SecurityStack exhaustion in the RouterOS HTTP server
CVE-2018-1158 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server through recursive JSON parsing. It affects versions prior to 6.40.9 and 6.42.7. To mitigate the risk, upgrade to a later version or restrict access to the web management service to the administration network only.
SecurityDenial of Service on the FTP service in RouterOS
CVE-2018-10070 is an Uncontrolled Resource Consumption vulnerability that allows a remote unauthenticated attacker to exhaust the router's CPU and RAM by sending malicious FTP requests. The affected device is MikroTik Version 6.41.4, which reboots after approximately 10 minutes. To protect yourself, you must update the firmware to a later version or disable the FTP service if it is not strictly necessary.