Updates
Update RouterOS, RouterBOOT firmware, release channels, downgrade, Netinstall: all dojo articles on this topic.

Buffer overflow in the SMB server of RouterOS
CVE-2020-22844 is a buffer overflow in the SMB server of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service through malicious SMB requests. The vulnerability specifically affects version 6.47 and is not known to be actively exploited. To mitigate the risk, you must update the firmware or disable the SMB service if it is not in use.
SecurityReflected XSS in the Hotspot login page
CVE-2021-3014 is a reflected Cross-Site Scripting (XSS) vulnerability in the Hotspot service login page in MikroTik RouterOS. It affects RouterOS versions published up to January 4, 2021. To mitigate the risk, you must update the firmware to a later version or disable access to the Hotspot login page from untrusted networks.
SecurityInteger underflow in the RouterOS SMB server
CVE-2019-16160 is an integer underflow in the RouterOS SMB server that allows an unauthenticated remote attacker to crash the service. RouterOS versions prior to 6.45.5 are affected. To mitigate the risk, upgrade to a later version or disable the SMB service if not required.
SecurityPlaintext password in the WinBox configuration file
WinBox 3.22 and earlier versions save the user password in unencrypted text in the configuration file if the "Keep Password" option is enabled and no Master Password is set. Since these are the default settings, an attacker with access to the file can recover the credentials to access the router. You must update WinBox to a later version or disable the password saving option.
SecurityPath traversal vulnerability in WinBox
CVE-2020-5720 is a path traversal vulnerability in WinBox, the graphical client for managing MikroTik routers. It affects all WinBox versions prior to 3.21 and allows the creation of arbitrary files if the client connects to a malicious endpoint or suffers a man-in-the-middle attack. To mitigate the risk, you must update WinBox to version 3.21 or higher and restrict access to the service only from the trusted administration network.
SecurityDNS cache poisoning vulnerability in RouterOS
CVE-2019-3979 is a high-risk vulnerability that allows a malicious DNS server to poison the router's DNS cache by adding unsolicited A records. It affects RouterOS versions 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier. To mitigate the risk, you must update the firmware or block incoming DNS traffic from the untrusted network.
SecurityDNS Cache Poisoning Vulnerability in RouterOS
CVE-2019-3978 allows unauthenticated remote attackers to generate DNS queries toward arbitrary servers, potentially poisoning the router's DNS cache. RouterOS 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier, are affected. You must update the firmware to a later version or block access to the DNS service from untrusted networks.
SecurityRouterOS autoupgrade vulnerability
CVE-2019-3977 allows a remote attacker to force the router to download and install an older version of RouterOS via the autoupgrade function, potentially resetting system credentials. Versions 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier, are affected. You must disable the autoupgrade function or update the firmware to a later version not listed as vulnerable.
SecurityArbitrary directory creation in RouterOS
CVE-2019-3976 allows an authenticated user to create an arbitrary directory and enable the developer shell by installing a malicious package. It affects RouterOS 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier. The administrator must update the firmware to a version later than those indicated to eliminate the risk.
SecurityPath Traversal Vulnerability in RouterOS (CVE-2019-15055)
CVE-2019-15055 is a path traversal vulnerability that allows authenticated users to delete arbitrary files on MikroTik RouterOS systems. The attack can lead to the reset of credential storage, permitting access to the management interface as an administrator without authentication. You must update the firmware to a version later than the vulnerable releases indicated in the description.
SecurityStack exhaustion in RouterOS WebFig
CVE-2019-13955 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server by sending malicious HTTP requests. It affects RouterOS versions prior to 6.44.5 on the long-term release branch. To mitigate the risk, upgrade to a later version or disable the WebFig service if not required.
SecurityMemory exhaustion in the RouterOS HTTP server
CVE-2019-13954 is a vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server by sending malicious HTTP requests, potentially causing a system reboot. It affects RouterOS versions prior to 6.44.5. To protect yourself, you must update to a later version or disable the web service if not in use.
SecurityCertificate Validation Vulnerability in RouterOS
CVE-2025-42611 is a certificate validation vulnerability that may allow authentication bypass in services such as OpenVPN, CAPsMAN, and Dot1X. It affects RouterOS versions up to 7.20.x. The fixed version has not yet been announced; as of the article date, the vulnerability is not known to be actively exploited.