Vulnerability index

Browse CVEs

86 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Routeros HIGH 7.5
CVE-2019-3977

RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download from when using the autoupgr…

Fix: after 6.45.6
Fix from $1,950 2019-10-29
Routeros HIGH 7.5
CVE-2019-3978EPSS 10%

RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries…

Fix: after 6.45.6
Fix from $1,950 2019-10-29
Routeros HIGH 7.5
CVE-2019-3979

RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router adds all A records to its DNS …

Fix: after 6.45.6
Fix from $1,950 2019-10-29
Routeros MEDIUM 6.5
CVE-2019-15055

MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary fil…

Fix: after 6.45.3
Fix from $1,600 2019-08-26
Routeros MEDIUM 6.5
CVE-2019-13954

Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP request, an authenticated remo…

Fix: 6.44.5+
Fix from $1,600 2019-07-26
Routeros MEDIUM 6.5
CVE-2019-13955

Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to stack exhaustion. By sending a crafted HTTP request, an authenticated remot…

Fix: 6.44.5+
Fix from $1,600 2019-07-26
Routeros HIGH 7.5
CVE-2019-13074

A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device…

Fix: after 6.44.3
Fix from $1,950 2019-07-03
Routeros HIGH 8.1
CVE-2019-3943

MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated…

Fix: after 6.43.12
Fix from $1,950 2019-04-10
Routeros HIGH 7.5
CVE-2019-3924EPSS 16%

MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defi…

Fix: 6.42.12 / 6.43.12+
Fix from $1,950 2019-02-20
Routeros HIGH 8.8
CVE-2018-1156EPSS 7%

Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to stack buffer overflow through the license upgrade interface. This vulnerability could the…

Fix: 6.40.9 / 6.42.7+
Fix from $1,950 2018-08-23
Routeros MEDIUM 6.5
CVE-2018-1157

Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory exhaustion vulnerability. An authenticated remote attacker can crash the HTTP se…

Fix: 6.40.9 / 6.42.7+
Fix from $1,600 2018-08-23
Routeros MEDIUM 6.5
CVE-2018-1158

Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a stack exhaustion vulnerability. An authenticated remote attacker can crash the HTTP ser…

Fix: 6.40.9 / 6.42.7+
Fix from $1,600 2018-08-23
Routeros MEDIUM 6.5
CVE-2018-1159

Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory corruption vulnerability. An authenticated remote attacker can crash the HTTP se…

Fix: 6.40.9 / 6.42.7+
Fix from $1,600 2018-08-23
Routeros CRITICAL 9.1
CVE-2018-14847 KEVEPSS 96%

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary …

Fix: after 6.42
Fix from $2,300 2018-08-02
Router Firmware HIGH 7.5
CVE-2018-10070EPSS 13%

A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sendi…

No fix yet
Fix from $1,950 2018-04-16
Routeros HIGH 8.1
CVE-2018-10066

An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification allows a remote unauthenticated attacker capable…

No fix yet
Fix from $1,950 2018-04-13
Routeros CRITICAL 9.8
CVE-2018-7445 KEVEPSS 61%

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to th…

Fix: 6.41.3+
Fix from $2,300 2018-03-19
Routerboard HIGH 7.5
CVE-2017-17537

MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and send…

No fix yet
Fix from $1,950 2017-12-13
Router Firmware HIGH 7.5
CVE-2017-17538EPSS 8%

MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.

No fix yet
Fix from $1,950 2017-12-13
Routeros HIGH 7.5
CVE-2017-8338

A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on …

No fix yet
Fix from $1,950 2017-05-18
Routeros HIGH 7.5
CVE-2017-7285EPSS 19%

A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all ava…

No fix yet
Fix from $1,950 2017-03-29
Routeros HIGH 7.5
CVE-2017-6444EPSS 13%

The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows …

No fix yet
Fix from $1,950 2017-03-12
Routeros MEDIUM 5.9
CVE-2017-6297

The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attac…

No fix yet
Fix from $1,600 2017-02-27
Routeros MEDIUM 6.8
CVE-2015-2350

Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administ…

Fix: after 5.0
Fix from $1,600 2015-03-19
Routeros MEDIUM 6.4
CVE-2012-6050EPSS 9%

The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router vers…

No fix yet
Fix from $1,600 2012-11-27
Routeros MEDIUM 6.4
CVE-2008-6976EPSS 9%

MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SN…

Fix: after 3.13
Fix from $1,600 2009-08-19