Updates
Update RouterOS, RouterBOOT firmware, release channels, downgrade, Netinstall: all dojo articles on this topic.

RADVD Vulnerability in RouterOS
CVE-2023-32154 is a remote code execution (RCE) vulnerability in the Router Advertisement Daemon (RADVD) of MikroTik RouterOS. It affects versions 6.49.7 Stable and earlier, allowing nearby network attackers to execute code with root privileges without authentication. The fixed version has not yet been announced; you must monitor official vendor announcements.
SecurityUnauthorized access to the REST API in RouterOS
CVE-2023-41570 is an access control vulnerability in the RouterOS REST API that allows an authenticated user with low privileges to access sensitive data. It affects versions 7.1 through 7.11. Updating to version 7.12 or later resolves the issue; alternatively, you must restrict access to the REST API to trusted hosts only.
SecurityHeap corruption in RouterOS 6 WebFig
CVE-2023-30800 is a heap memory corruption flaw in the web server of RouterOS version 6. An unauthenticated remote attacker can crash the web interface by sending a malicious HTTP request. The vulnerability is fixed in stable version 6.49.10; RouterOS version 7 is not affected.
SecurityArbitrary code execution on RouterOS
CVE-2023-30799 is a privilege escalation vulnerability that allows an authenticated attacker with an admin account to obtain super-admin privileges and execute arbitrary code. It affects stable versions of RouterOS prior to 6.49.7 and long-term versions up to and including 6.48.6. Updating to a patched version is the primary measure to mitigate the risk.
SecurityDenial of Service in the RouterOS SSH Server
CVE-2020-20021 is a Denial of Service (DoS) vulnerability affecting the SSH server in MikroTik Router v6.46.3 and earlier versions. A remote attacker can cause a service interruption by exploiting a misconfigured SSH daemon. To mitigate the risk, you must update the firmware to a later version or restrict access to the SSH service to the trusted administration network only.
SecurityDoS Vulnerability in bridge2 of RouterOS v6.40.5
CVE-2023-24094 is an Out-of-bounds Write vulnerability in the bridge2 component of MikroTik RouterOS v6.40.5 that allows a remote attacker to cause a Denial of Service (DoS) via malicious packets. The vulnerability is classified as HIGH with a CVSS score of 7.5. Corrective versions and specific mitigation details have not yet been disclosed in available sources.
SecurityOut-of-bounds read in SNMP on RouterOS
CVE-2022-45315 is a critical vulnerability (CVSS 9.8) that allows an authenticated attacker to execute arbitrary code via a malicious SNMP packet. It affects RouterOS versions prior to 7.6. To mitigate the risk, upgrade to a later stable version or disable the SNMP service if not required.
SecurityOut-of-bounds Read in the Hotspot Process
CVE-2022-45313 is an Out-of-bounds Read vulnerability in the hotspot process of RouterOS, allowing arbitrary code execution via a manipulated nova message. It affects RouterOS versions prior to 7.5. To mitigate the risk, you must update to a stable version later than 7.5 or disable the hotspot service if not in use.
SecurityCritical vulnerability in the RouterOS web server
CVE-2017-20149 is a critical vulnerability (CVSS 9.8) in the RouterOS web server that allows an unauthenticated remote user to execute arbitrary code. It affects versions prior to 6.37.5 and 6.38.5. You must immediately update the firmware to a later version to eliminate the risk.
Security35 DoS vulnerabilities in RouterOS 6.44–6.48: who is at risk and which version to install
Between 2021 and 2022, 35 nearly identical CVEs were published for RouterOS 6: in each case, a system process (console, sniffer, resolver, lcdstat, and others) crashes when it receives crafted input, causing a denial of service on the router. They all have a CVSS score of 6.5 and share one common factor that significantly reduces the risk: valid credentials on the router are required. They affect versions from 6.44 to 6.48.3; the solution is to upgrade to the latest 6.49 or to RouterOS 7, and in the meantime, restrict who can log in.
SecurityCritical vulnerability in the RouterOS container package
CVE-2022-34960 is a critical vulnerability (CVSS 9.8) in the MikroTik RouterOS 7.4beta4 container package that allows an attacker to mount arbitrary files at any location on the host device. It exclusively affects administrators who have installed and enabled the container package in device mode. Immediate mitigation consists of updating to a fixed version or disabling the service if not used.
SecurityBuffer overflow in the RouterOS SCEP server
CVE-2021-41987 is a critical vulnerability (CVSS 8.1) in the RouterOS SCEP server that allows remote code execution. It affects versions 6.46.8, 6.47.9, and 6.47.10. You must update the firmware to a later version not listed as vulnerable or disable the SCEP service if not in use.
SecurityBuffer overflow in the FTP service of RouterOS 6.47
CVE-2020-22845 is a buffer overflow in the FTP service of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service via malicious FTP requests. The vulnerability has HIGH severity (CVSS 7.5) and specifically affects version 6.47. To mitigate the risk, you must update to a later version or disable the FTP service if not strictly necessary.