Vulnerability index

Browse CVEs

86 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-6443 Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on … Routeros 7.20+ Fix from $1,9502025-06-25 HIGH 7.5 CVE-2024-54952 MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sen… Routeros Mitigation only Fix from $1,9502025-05-29 MEDIUM 5.4 CVE-2024-54772 An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A pa… Routeros 6.49.18 / 7.18+ Fix from $1,6002025-02-11 HIGH 7.5 CVE-2023-32154 Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbi… Routeros 6.48.7+ Fix from $1,9502024-05-03 MEDIUM 5.3 CVE-2023-41570 MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API. Routeros 7.12+ Fix from $1,6002023-11-14 HIGH 7.5 CVE-2023-30800 The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt t… Routeros 6.49.10+ Fix from $1,9502023-09-07 HIGH 7.2 CVE-2023-30799 MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attack… Routeros 6.49.7+ Fix from $1,9502023-07-19 HIGH 7.5 CVE-2020-20021 An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon. Routeros after 6.46.3 Fix from $1,9502023-07-12 HIGH 7.5 CVE-2023-24094 An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets. Routeros No fix yet Fix from $1,9502023-03-27 CRITICAL 9.8 CVE-2022-45315 Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated att… Routeros 7.6+ Fix from $2,3002022-12-05 HIGH 8.8 CVE-2022-45313 Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to e… Routeros 7.5+ Fix from $1,9502022-12-05 CRITICAL 9.8 CVE-2017-20149 The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthe… Routeros 6.37.5 / 6.38.5+ Fix from $2,3002022-10-15 MEDIUM 6.5 CVE-2022-36522 Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vuln… Routeros after 6.48.3 Fix from $1,6002022-08-26 CRITICAL 9.8 CVE-2022-34960 The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations … Routeros No fix yet Fix from $2,3002022-08-25 MEDIUM 6.5 CVE-2021-36613 Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause … Routeros 6.48.2+ Fix from $1,6002022-05-11 MEDIUM 6.5 CVE-2021-36614 Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An authenticated remote attacker c… Routeros 6.48.2+ Fix from $1,6002022-05-11 HIGH 8.1 CVE-2021-41987EPSS 16% In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution… Routeros No fix yet Fix from $1,9502022-03-16 HIGH 7.5 CVE-2020-22844 A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests. Routeros Mitigation only Fix from $1,9502022-02-28 HIGH 7.5 CVE-2020-22845 A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted FTP requests. Routeros Mitigation only Fix from $1,9502022-02-28 MEDIUM 6.5 CVE-2020-20219 Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process. An authenticated remote… Routeros No fix yet Fix from $1,6002021-07-21 MEDIUM 6.5 CVE-2020-20221 Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm process. An au… Routeros 6.44.6+ Fix from $1,6002021-07-21 MEDIUM 6.5 CVE-2020-20262 Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An auth… Routeros 6.47+ Fix from $1,6002021-07-21 MEDIUM 6.5 CVE-2020-20248 Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can c… Routeros No fix yet Fix from $1,6002021-07-19 MEDIUM 6.5 CVE-2020-20249 Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenti… Routeros 6.47+ Fix from $1,6002021-07-19 MEDIUM 6.5 CVE-2020-20230 Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can caus… Routeros 6.47+ Fix from $1,6002021-07-19 MEDIUM 6.5 CVE-2020-20231 Mikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in the /nova/bin/detnet process. An authenticated remo… Routeros after 6.48.3 Fix from $1,6002021-07-14 MEDIUM 6.5 CVE-2020-20252 Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote… Routeros 6.47+ Fix from $1,6002021-07-13 MEDIUM 6.5 CVE-2020-20250 Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote… Routeros 6.47+ Fix from $1,6002021-07-13 MEDIUM 6.5 CVE-2020-20217 Mikrotik RouterOs before 6.47 (stable tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/route process. An authen… Routeros 6.47+ Fix from $1,6002021-07-08 MEDIUM 6.5 CVE-2020-20211 Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote a… Routeros No fix yet Fix from $1,6002021-07-07