Vulnerability index

Browse CVEs

86 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Routeros HIGH 7.2
CVE-2025-6443

Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on …

Fix: 7.20+
Fix from $1,950 2025-06-25
Routeros HIGH 7.5
CVE-2024-54952

MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sen…

Mitigation only
Fix from $1,950 2025-05-29
Routeros MEDIUM 5.4
CVE-2024-54772

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A pa…

Fix: 6.49.18 / 7.18+
Fix from $1,600 2025-02-11
Routeros HIGH 7.5
CVE-2023-32154

Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbi…

Fix: 6.48.7+
Fix from $1,950 2024-05-03
Routeros MEDIUM 5.3
CVE-2023-41570

MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.

Fix: 7.12+
Fix from $1,600 2023-11-14
Routeros HIGH 7.5
CVE-2023-30800

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt t…

Fix: 6.49.10+
Fix from $1,950 2023-09-07
Routeros HIGH 7.2
CVE-2023-30799

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attack…

Fix: 6.49.7+
Fix from $1,950 2023-07-19
Routeros HIGH 7.5
CVE-2020-20021

An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.

Fix: after 6.46.3
Fix from $1,950 2023-07-12
Routeros HIGH 7.5
CVE-2023-24094

An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets.

No fix yet
Fix from $1,950 2023-03-27
Routeros CRITICAL 9.8
CVE-2022-45315

Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated att…

Fix: 7.6+
Fix from $2,300 2022-12-05
Routeros HIGH 8.8
CVE-2022-45313

Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to e…

Fix: 7.5+
Fix from $1,950 2022-12-05
Routeros CRITICAL 9.8
CVE-2017-20149

The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthe…

Fix: 6.37.5 / 6.38.5+
Fix from $2,300 2022-10-15
Routeros MEDIUM 6.5
CVE-2022-36522

Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vuln…

Fix: after 6.48.3
Fix from $1,600 2022-08-26
Routeros CRITICAL 9.8
CVE-2022-34960

The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations …

No fix yet
Fix from $2,300 2022-08-25
Routeros MEDIUM 6.5
CVE-2021-36613

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause …

Fix: 6.48.2+
Fix from $1,600 2022-05-11
Routeros MEDIUM 6.5
CVE-2021-36614

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An authenticated remote attacker c…

Fix: 6.48.2+
Fix from $1,600 2022-05-11
Routeros HIGH 8.1
CVE-2021-41987EPSS 16%

In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution…

No fix yet
Fix from $1,950 2022-03-16
Routeros HIGH 7.5
CVE-2020-22844

A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.

Mitigation only
Fix from $1,950 2022-02-28
Routeros HIGH 7.5
CVE-2020-22845

A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted FTP requests.

Mitigation only
Fix from $1,950 2022-02-28
Routeros MEDIUM 6.5
CVE-2020-20219

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process. An authenticated remote…

No fix yet
Fix from $1,600 2021-07-21
Routeros MEDIUM 6.5
CVE-2020-20221

Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm process. An au…

Fix: 6.44.6+
Fix from $1,600 2021-07-21
Routeros MEDIUM 6.5
CVE-2020-20262

Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An auth…

Fix: 6.47+
Fix from $1,600 2021-07-21
Routeros MEDIUM 6.5
CVE-2020-20248

Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can c…

No fix yet
Fix from $1,600 2021-07-19
Routeros MEDIUM 6.5
CVE-2020-20249

Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenti…

Fix: 6.47+
Fix from $1,600 2021-07-19
Routeros MEDIUM 6.5
CVE-2020-20230

Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can caus…

Fix: 6.47+
Fix from $1,600 2021-07-19
Routeros MEDIUM 6.5
CVE-2020-20231

Mikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in the /nova/bin/detnet process. An authenticated remo…

Fix: after 6.48.3
Fix from $1,600 2021-07-14
Routeros MEDIUM 6.5
CVE-2020-20252

Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote…

Fix: 6.47+
Fix from $1,600 2021-07-13
Routeros MEDIUM 6.5
CVE-2020-20250

Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote…

Fix: 6.47+
Fix from $1,600 2021-07-13
Routeros MEDIUM 6.5
CVE-2020-20217

Mikrotik RouterOs before 6.47 (stable tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/route process. An authen…

Fix: 6.47+
Fix from $1,600 2021-07-08
Routeros MEDIUM 6.5
CVE-2020-20211

Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote a…

No fix yet
Fix from $1,600 2021-07-07