Skip to content
Topic

Updates

Update RouterOS, RouterBOOT firmware, release channels, downgrade, Netinstall: all dojo articles on this topic.

Illustrazione per CVE-2019-13074
Security
CVE-2019-13074

Memory exhaustion in the RouterOS FTP daemon

CVE-2019-13074 is a vulnerability in the RouterOS FTP daemon that allows a remote attacker to exhaust available memory, causing the device to reboot. It affects versions up to and including 6.44.3. To mitigate the risk, disable the FTP service or upgrade to a later version, if available.

2 min read
Illustrazione per CVE-2026-7668Security
CVE-2026-7668

Out-of-bounds read in SCEP Endpoint

CVE-2026-7668 is an out-of-bounds read vulnerability in the SCEP Endpoint component of RouterOS 6.49.8, exploitable remotely without authentication. It affects only version 6.49.8; the vendor recommends upgrading to the latest available v6.x or 7.x version. It is not known to be actively exploited and is not included in the CISA KEV catalog.

High · 7.3
Illustrazione per CVE-2019-3943Security
CVE-2019-3943

Directory traversal in RouterOS via Winbox and HTTP

CVE-2019-3943 is a directory traversal vulnerability that allows an authenticated user to read and write files outside the /rw/disk sandbox directory via the HTTP or Winbox interfaces. It affects Stable versions 6.43.12 and earlier, Long-term versions 6.42.12 and earlier, and Testing versions 6.44beta75 and earlier. You must update to a version later than those indicated or restrict access to the affected interfaces from untrusted networks.

High · 8.1
Illustrazione per CVE-2019-3924Security
CVE-2019-3924

Interception vulnerability in RouterOS

CVE-2019-3924 is an interception vulnerability that allows a remote unauthenticated attacker to issue user-defined network requests to WAN and LAN clients, enabling firewall bypass or network scanning. Affected versions are long-term 6.42.11 and earlier, and stable 6.43.11 and earlier. To protect yourself, you must upgrade to a version later than those indicated.

High · 7.5
Illustrazione per CVE-2018-1159Security
CVE-2018-1159

Memory vulnerability in the RouterOS HTTP server

CVE-2018-1159 is a memory corruption vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server. Versions prior to 6.40.9 and 6.42.7 are affected. To protect yourself, you must upgrade to a later version or restrict access to the web management service.

Illustrazione per CVE-2018-1158Security
CVE-2018-1158

Stack exhaustion in the RouterOS HTTP server

CVE-2018-1158 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server through recursive JSON parsing. It affects versions prior to 6.40.9 and 6.42.7. To mitigate the risk, upgrade to a later version or restrict access to the web management service to the administration network only.

Illustrazione per CVE-2018-1157Security
CVE-2018-1157

Memory exhaustion in the RouterOS HTTP server

CVE-2018-1157 is a vulnerability that allows an authenticated attacker to crash the HTTP server and, in some cases, reboot the system. It affects RouterOS versions prior to 6.40.9 and 6.42.7. To protect yourself, you must update to a later version or disable the web service if not in use.

Illustrazione per CVE-2018-1156Security
CVE-2018-1156

Buffer overflow in the RouterOS license update interface

CVE-2018-1156 is an Out-of-bounds Write (CWE-787) vulnerability in RouterOS versions prior to 6.40.9 and 6.42.7. A remote authenticated attacker could theoretically execute arbitrary code on the system through the license update interface. To mitigate the risk, you must update the firmware to the fixed versions.

Illustrazione per CVE-2018-14847Security
CVE-2018-14847

WinBox Vulnerability in RouterOS

CVE-2018-14847 is a critical vulnerability in the WinBox component of MikroTik RouterOS that allows an unauthenticated attacker to read arbitrary files and an authenticated attacker to write new ones. The vulnerability is present in RouterOS versions up to and including 6.42 and is listed in the CISA KEV catalog, indicating active exploitation. You must update the firmware to a version later than 6.42 and restrict access to the WinBox service to the management network.

Critical · 9.1Exploited
Illustrazione per CVE-2018-10070Security
CVE-2018-10070

Denial of Service on the FTP service in RouterOS

CVE-2018-10070 is an Uncontrolled Resource Consumption vulnerability that allows a remote unauthenticated attacker to exhaust the router's CPU and RAM by sending malicious FTP requests. The affected device is MikroTik Version 6.41.4, which reboots after approximately 10 minutes. To protect yourself, you must update the firmware to a later version or disable the FTP service if it is not strictly necessary.

Illustrazione per CVE-2018-7445Security
CVE-2018-7445

Buffer overflow in the SMB service of RouterOS

CVE-2018-7445 is a critical vulnerability (CVSS 9.8) in the SMB service of RouterOS that allows an unauthenticated attacker to execute code. It affects all RouterOS versions prior to 6.41.3. The vulnerability is listed in the CISA KEV catalog and requires applying updates according to the vendor's instructions.

Critical · 9.8Exploited
Illustrazione per CVE-2017-17538Security
CVE-2017-17538

Denial of Service via ICMP on RouterOS v6.40.5

The CVE-2017-17538 vulnerability allows a remote attacker to cause a denial of service by sending a massive sequence of ICMP packets. It affects MikroTik devices running RouterOS version 6.40.5. To mitigate the risk, you must update the firmware to a later version or apply network filters to limit ICMP traffic.

Illustrazione per CVE-2008-0680Security
CVE-2008-0680

SNMP Vulnerability in RouterOS 3.2

CVE-2008-0680 is a vulnerability that allows a remote attacker to cause the SNMP daemon to crash by sending a malicious SNMP SET request. It affects MikroTik RouterOS version 3.2 and earlier. To mitigate the risk, you must update the operating system to a later version or disable the SNMP service if it is not used.