Skip to content
VulniPulse
Medium5.4MikroTik

Medium [CVE-2024-54772] MikroTik RouterOS: Issue Summary A vulnerability has been identified in the WinBox service, where a discrepancy in response size between connection…

This medium-severity MikroTik advisory covers CVE-2024-54772 affecting MikroTik RouterOS, Winbox.

CVE-2024-54772 Published Feb 11, 2025Updated by vendor Jun 17, 2026
Affected products & platforms
MikroTikRouterOSWinbox / The Dude
Open vendor advisory

Android app · Google Play

Monitor future MikroTik CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Issue Summary A vulnerability has been identified in the WinBox service, where a discrepancy in response size between connection attempts with valid and invalid usernames allows attackers to confirm if user accounts exists via brute forcing the login process.

In other words, when attacker tries to log into the device, by examining the response, the attacker can deduce if such a user exists on the device. Even if username is found, password still needs to be guessed as well.

Affected Versions RouterOS versions prior to 6.49.18 and 7.18. Recommended Actions Update RouterOS – Upgrade to 6.49.18, 7.18, or a newer version to patch the vulnerability.

Monitor for unusual login attempts – Review router logs for suspicious authentication activity and take action accordingly. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so WinBox and other management services are not reachable from untrusted networks.

Mitigation strategies for devices that cannot be updated immediately Restrict WinBox Access. Firewall the WinBox port on public interfaces and untrusted networks.

Affected products named by the advisory: MikroTik RouterOS.

Affected versions
  • 43.13

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Fixed versions
  • 6.49.18
  • 7.18

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade RouterOS to a fixed release: 6.49.18, 7.18.
  • MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so WinBox and other management services are not reachable from untrusted networks.
  • Restrict WinBox Access.
  • Limit connections to trusted IP addresses using the “IP → Services” menu to specify allowed sources (e.
  • Restrict MAC-WinBox connections to trusted interfaces using: /tool mac-server mac-winbox set allowed-interface-list=<trusted-interface-list> If your device is running the default configuration with firewall enabled, WinBox service is already limited to LAN access.

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.