Critical [CVE-2023-30799] RouterOS: MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue.
This critical-severity MikroTik advisory covers CVE-2023-30799 affecting MikroTik RouterOS.
Android app · Google Play
Monitor future MikroTik CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A new CVE has been published, which describes a policy elevation issue, where a logged in administrator with “policy” permissions (able to grant additional permissions to any user on the router), is also able to send crafted configuration commands, that are exchanged internally by the router software components and normally are rejected when sent by a user.
This can be used as a stepping stone to execute arbitrary code on the router, allowing the connected user to gain control of the underlying operating system upon which RouterOS runs. To be able to use this discovered exploit, one would need administrative access to RouterOS, i.e. a known username and password, as well as a ways to connect (no firewall).
This is not the only way how a logged in administrator user with such a high access level (as required for this exploit) can compromise the router.
Other possibilities include: saving, modifying and restoring configuration backup; installing additional software packages; using another device on the local network to perform network reinstall of the router to a known vulnerable version. Affected product named by the advisory: MikroTik RouterOS.
- 6.48.6
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
- 7.7
- 6.49.7
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- Upgrade RouterOS to a fixed release: 7.7, 6.49.7.
- Keep RouterOS up to date, use check-for-updates, to make sure you are running the latest RouterOS version.
- MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so management services are not reachable from untrusted networks.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.