WinBox and WebFig
WinBox, WebFig, and the router’s web management service: all dojo articles on this topic.

Stack exhaustion in RouterOS WebFig
CVE-2019-13955 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server by sending malicious HTTP requests. It affects RouterOS versions prior to 6.44.5 on the long-term release branch. To mitigate the risk, upgrade to a later version or disable the WebFig service if not required.
SecurityMemory exhaustion in the RouterOS HTTP server
CVE-2019-13954 is a vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server by sending malicious HTTP requests, potentially causing a system reboot. It affects RouterOS versions prior to 6.44.5. To protect yourself, you must update to a later version or disable the web service if not in use.
SecurityDirectory traversal in RouterOS via Winbox and HTTP
CVE-2019-3943 is a directory traversal vulnerability that allows an authenticated user to read and write files outside the /rw/disk sandbox directory via the HTTP or Winbox interfaces. It affects Stable versions 6.43.12 and earlier, Long-term versions 6.42.12 and earlier, and Testing versions 6.44beta75 and earlier. You must update to a version later than those indicated or restrict access to the affected interfaces from untrusted networks.
SecurityMemory vulnerability in the RouterOS HTTP server
CVE-2018-1159 is a memory corruption vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server. Versions prior to 6.40.9 and 6.42.7 are affected. To protect yourself, you must upgrade to a later version or restrict access to the web management service.
SecurityStack exhaustion in the RouterOS HTTP server
CVE-2018-1158 is a stack exhaustion vulnerability that allows an authenticated attacker to crash the RouterOS HTTP server through recursive JSON parsing. It affects versions prior to 6.40.9 and 6.42.7. To mitigate the risk, upgrade to a later version or restrict access to the web management service to the administration network only.
SecurityMemory exhaustion in the RouterOS HTTP server
CVE-2018-1157 is a vulnerability that allows an authenticated attacker to crash the HTTP server and, in some cases, reboot the system. It affects RouterOS versions prior to 6.40.9 and 6.42.7. To protect yourself, you must update to a later version or disable the web service if not in use.
SecurityWinBox Vulnerability in RouterOS
CVE-2018-14847 is a critical vulnerability in the WinBox component of MikroTik RouterOS that allows an unauthenticated attacker to read arbitrary files and an authenticated attacker to write new ones. The vulnerability is present in RouterOS versions up to and including 6.42 and is listed in the CISA KEV catalog, indicating active exploitation. You must update the firmware to a version later than 6.42 and restrict access to the WinBox service to the management network.