
Password and access
Password, users, SSH keys, factory credentials: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

CVE-2018-14847: Recovering plaintext passwords from user.dat on RouterOS v6
We reproduced the CVE-2018-14847 vulnerability on RouterOS v6, confirming that an unauthenticated attacker can read the user.dat file and recover plaintext passwords due to a weak XOR transformation. The issue is fixed in versions 6.40.8, 6.42.11, and 6.49.7, where access to the file is denied.
SecurityCleartext credentials on SPI flash
MikroTik firmware 7.19.4 stores authentication credentials and network state in cleartext on non-volatile memory. An attacker with physical access to the device can extract this data from an SPI flash dump without authenticating. No corrective versions or specific mitigations have been communicated by the vendor.
SecurityUnauthorized file read in WebFig
CVE-2026-67281 is an unauthenticated file read vulnerability in the WebFig service of RouterOS that allows an attacker to access restricted files, including credential databases. It affects 7.x versions lower than 7.23.4 and 7.24.2. You must update the firmware or disable remote access to WebFig.
SecurityRouterOS API Vulnerability: Brute-Force Risk
CVE-2026-16347 is a high-severity vulnerability (CVSS 8.8) affecting all RouterOS versions due to the lack of effective limits on API authentication attempts. An attacker can perform a high volume of login attempts to guess administrative credentials. Immediate mitigation consists of disabling the API if not required or restricting access to authorized management hosts only, pending a corrective release.
DojoBasic hardening of a MikroTik router with RouterOS 7
A MikroTik freshly reset with no-defaults=yes has no firewall: it is fine on the bench for learning, but it should never be put on the network like that. Before installing it, you need seven hardening steps: update RouterOS, replace the admin user, disable unused services and restrict the others to authorized addresses, close service ports on external interfaces, a minimal firewall that blocks everything coming from the internet, and a VPN for remote management.
SecurityWebFig Exposed in Clear on RouterOS and SwOS
CVE-2025-61481 exposes the WebFig management interface of RouterOS v.7.14.2 and SwOS v.2.18 via unencrypted HTTP, allowing a man-in-the-middle attacker to inject JavaScript into the administrator's browser and intercept credentials. The vulnerability is classified as critical with a CVSS score of 10.0. To mitigate the risk, disable WebFig if not necessary or restrict access exclusively to the trusted management network.
SecurityAccount Enumeration in Winbox on RouterOS
CVE-2024-54772 allows an attacker to identify valid usernames on a MikroTik router by analyzing differences in Winbox service response times. Affected versions include long-term 6.43.13 through 6.49.13 and stable 6.43 through 7.17.2. To mitigate the risk, upgrade to version 6.49.18 or later and restrict Winbox access to the management network.
SecurityArbitrary code execution on RouterOS
CVE-2023-30799 is a privilege escalation vulnerability that allows an authenticated attacker with an admin account to obtain super-admin privileges and execute arbitrary code. It affects stable versions of RouterOS prior to 6.49.7 and long-term versions up to and including 6.48.6. Updating to a patched version is the primary measure to mitigate the risk.
SecurityArbitrary File Write via FTP in RouterOS
CVE-2021-27221 allows a remote authenticated user with an FTP policy to create or overwrite arbitrary .rsc files using the /export command. This flaw affects RouterOS 6.47.9, where the vendor considers this behavior intentional due to how user policies work. To mitigate the risk, you must disable the cleartext FTP service or ensure that only trusted users with appropriate policies can access it.
SecurityPlaintext password in the WinBox configuration file
WinBox 3.22 and earlier versions save the user password in unencrypted text in the configuration file if the "Keep Password" option is enabled and no Master Password is set. Since these are the default settings, an attacker with access to the file can recover the credentials to access the router. You must update WinBox to a later version or disable the password saving option.
SecurityWinbox Vulnerability: Man-in-the-Middle Attack
CVE-2019-3981 is a vulnerability in MikroTik Winbox 3.20 and earlier that allows an attacker positioned between the client and the router to perform an authentication downgrade and retrieve the username and MD5-hashed password. The risk arises when Winbox is reachable from untrusted networks. To mitigate the risk, you must update Winbox to a version later than 3.20 and restrict access to the service to the administration network only.
SecurityRouterOS autoupgrade vulnerability
CVE-2019-3977 allows a remote attacker to force the router to download and install an older version of RouterOS via the autoupgrade function, potentially resetting system credentials. Versions 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier, are affected. You must disable the autoupgrade function or update the firmware to a later version not listed as vulnerable.
SecurityWinBox Vulnerability in RouterOS
CVE-2018-14847 is a critical vulnerability in the WinBox component of MikroTik RouterOS that allows an unauthenticated attacker to read arbitrary files and an authenticated attacker to write new ones. The vulnerability is present in RouterOS versions up to and including 6.42 and is listed in the CISA KEV catalog, indicating active exploitation. You must update the firmware to a version later than 6.42 and restrict access to the WinBox service to the management network.