Skip to content
Topic

Updates

Update RouterOS, RouterBOOT firmware, release channels, downgrade, Netinstall: all dojo articles on this topic.

Illustrazione per Vulnerabilità RADVD in RouterOS
Security
CVE-2023-32154

RADVD Vulnerability in RouterOS

CVE-2023-32154 is a remote code execution (RCE) vulnerability in the Router Advertisement Daemon (RADVD) of MikroTik RouterOS. It affects versions 6.49.7 Stable and earlier, allowing nearby network attackers to execute code with root privileges without authentication. The fixed version has not yet been announced; you must monitor official vendor announcements.

2 min read
Illustrazione per CVE-2023-41570Security
CVE-2023-41570

Unauthorized access to the REST API in RouterOS

CVE-2023-41570 is an access control vulnerability in the RouterOS REST API that allows an authenticated user with low privileges to access sensitive data. It affects versions 7.1 through 7.11. Updating to version 7.12 or later resolves the issue; alternatively, you must restrict access to the REST API to trusted hosts only.

Medium · 5.3
Illustrazione per CVE-2023-30800Security
CVE-2023-30800

Heap corruption in RouterOS 6 WebFig

CVE-2023-30800 is a heap memory corruption flaw in the web server of RouterOS version 6. An unauthenticated remote attacker can crash the web interface by sending a malicious HTTP request. The vulnerability is fixed in stable version 6.49.10; RouterOS version 7 is not affected.

High · 7.5
Illustrazione per CVE-2023-30799Security
CVE-2023-30799

Arbitrary code execution on RouterOS

CVE-2023-30799 is a privilege escalation vulnerability that allows an authenticated attacker with an admin account to obtain super-admin privileges and execute arbitrary code. It affects stable versions of RouterOS prior to 6.49.7 and long-term versions up to and including 6.48.6. Updating to a patched version is the primary measure to mitigate the risk.

High · 7.2
Illustrazione per Denial of Service nel server SSH di RouterOSSecurity
CVE-2020-20021

Denial of Service in the RouterOS SSH Server

CVE-2020-20021 is a Denial of Service (DoS) vulnerability affecting the SSH server in MikroTik Router v6.46.3 and earlier versions. A remote attacker can cause a service interruption by exploiting a misconfigured SSH daemon. To mitigate the risk, you must update the firmware to a later version or restrict access to the SSH service to the trusted administration network only.

High · 7.5
Illustrazione per Vulnerabilità DoS in bridge2 di RouterOS v6.40.5Security
CVE-2023-24094

DoS Vulnerability in bridge2 of RouterOS v6.40.5

CVE-2023-24094 is an Out-of-bounds Write vulnerability in the bridge2 component of MikroTik RouterOS v6.40.5 that allows a remote attacker to cause a Denial of Service (DoS) via malicious packets. The vulnerability is classified as HIGH with a CVSS score of 7.5. Corrective versions and specific mitigation details have not yet been disclosed in available sources.

High · 7.5
Illustrazione per CVE-2022-45315Security
CVE-2022-45315

Out-of-bounds read in SNMP on RouterOS

CVE-2022-45315 is a critical vulnerability (CVSS 9.8) that allows an authenticated attacker to execute arbitrary code via a malicious SNMP packet. It affects RouterOS versions prior to 7.6. To mitigate the risk, upgrade to a later stable version or disable the SNMP service if not required.

Critical · 9.8
Illustrazione per CVE-2022-45313Security
CVE-2022-45313

Out-of-bounds Read in the Hotspot Process

CVE-2022-45313 is an Out-of-bounds Read vulnerability in the hotspot process of RouterOS, allowing arbitrary code execution via a manipulated nova message. It affects RouterOS versions prior to 7.5. To mitigate the risk, you must update to a stable version later than 7.5 or disable the hotspot service if not in use.

High · 8.8
Illustrazione per CVE-2017-20149Security
CVE-2017-20149

Critical vulnerability in the RouterOS web server

CVE-2017-20149 is a critical vulnerability (CVSS 9.8) in the RouterOS web server that allows an unauthenticated remote user to execute arbitrary code. It affects versions prior to 6.37.5 and 6.38.5. You must immediately update the firmware to a later version to eliminate the risk.

Critical · 9.8
Illustrazione per 35 vulnerabilità DoS in RouterOS 6.44–6.48: chi è a rischio e quale versione installareSecurity
35 CVEs · RouterOS 6.44–6.48

35 DoS vulnerabilities in RouterOS 6.44–6.48: who is at risk and which version to install

Between 2021 and 2022, 35 nearly identical CVEs were published for RouterOS 6: in each case, a system process (console, sniffer, resolver, lcdstat, and others) crashes when it receives crafted input, causing a denial of service on the router. They all have a CVSS score of 6.5 and share one common factor that significantly reduces the risk: valid credentials on the router are required. They affect versions from 6.44 to 6.48.3; the solution is to upgrade to the latest 6.49 or to RouterOS 7, and in the meantime, restrict who can log in.

Medium · 6.5
Illustrazione per CVE-2022-34960Security
CVE-2022-34960

Critical vulnerability in the RouterOS container package

CVE-2022-34960 is a critical vulnerability (CVSS 9.8) in the MikroTik RouterOS 7.4beta4 container package that allows an attacker to mount arbitrary files at any location on the host device. It exclusively affects administrators who have installed and enabled the container package in device mode. Immediate mitigation consists of updating to a fixed version or disabling the service if not used.

Critical · 9.8
Illustrazione per CVE-2021-41987Security
CVE-2021-41987

Buffer overflow in the RouterOS SCEP server

CVE-2021-41987 is a critical vulnerability (CVSS 8.1) in the RouterOS SCEP server that allows remote code execution. It affects versions 6.46.8, 6.47.9, and 6.47.10. You must update the firmware to a later version not listed as vulnerable or disable the SCEP service if not in use.

High · 8.1
Illustrazione per CVE-2020-22845Security
CVE-2020-22845

Buffer overflow in the FTP service of RouterOS 6.47

CVE-2020-22845 is a buffer overflow in the FTP service of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service via malicious FTP requests. The vulnerability has HIGH severity (CVSS 7.5) and specifically affects version 6.47. To mitigate the risk, you must update to a later version or disable the FTP service if not strictly necessary.

High · 7.5