Skip to content
VulniPulse

MikroTik RouterOS Vulnerabilities & Security Advisories

10 advisories tracked · MikroTik Security Announcements + NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published MikroTik advisory that VulniPulse classified as RouterOS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 6 high, 2 medium.

Android app · Google Play

Monitor MikroTik CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

MikroTik Security Announcements + NVD

MikroTik publishes official security announcements at mikrotik.com/supportsec, but has no machine-readable feed and its CVEs are assigned by several CNAs. VulniPulse joins NVD candidate metadata to the server-rendered official announcement index, then releases an alert only after fetching the linked article and verifying its CVE identity in the article heading or body. Covers RouterOS (v6/v7), SwOS, Winbox, The Dude and MikroTik router/switch hardware (hEX, CCR, CRS, cAP, wAP).

Latest MikroTik RouterOS advisories

High7.5MikroTik

High [CVE-2024-27686] Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash)

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

CVE-2024-27686
RouterOS
May 8, 2026
High8.8MikroTik

High [CVE-2025-10948] RouterOS: vulnerability has been found in MikroTik RouterOS 7.

A buffer overflow vulnerability has been discovered in MikroTik RouterOS 7, affecting the parse_json_element function within the libjson.so component. The vulnerability is triggered through the /rest/ip/address/print endpoint and can be exploited remotely. The exploit for this issue has been publicly disclosed and may be actively used. Upgrading to RouterOS version 7.20.1 or 7.21beta2 mitigates this issue. The vendor has confirmed that a fix has been implemented and plans to release a RouterOS update containing the patch. Users should upgrade to the latest available version to ensure full protection. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so REST API and management services are available only from trusted networks.

CVE-2025-10948
RouterOS
Sep 25, 2025
UnratedMikroTik

Unknown [CVE-2025-6563] RouterOS: cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2.

A cross-site scripting (XSS) vulnerability has been discovered in the hotspot functionality of MikroTik RouterOS, affecting versions below 7.19.2. An attacker can inject the javascript protocol via the dst parameter in a crafted URL. When a victim browses to this malicious URL and logs in through the hotspot page, the injected XSS payload executes in their browser. Additionally, the POST request used for login can be converted to a GET request. This allows an attacker to craft a URL that automatically logs the victim into the attacker’s account and triggers the payload, requiring no interaction beyond visiting the link. Users are advised to upgrade to RouterOS 7.20 or any later version to address this vulnerability. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall to protect router management services from untrusted networks; hotspot access should still be configured only as broadly as the deployment requires.

CVE-2025-6563
RouterOS
Jul 3, 2025
High7.2MikroTik

High [CVE-2025-6443] RouterOS: Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability.

An improper access control vulnerability has been identified in MikroTik RouterOS, related to the handling of VXLAN source IP addresses. This flaw allows remote attackers to bypass access restrictions on affected installations without requiring authentication. The specific issue exists within the processing of remote IP addresses during VXLAN traffic handling. The router fails to validate the remote IP address against configured values before allowing ingress traffic into the internal network. An attacker can exploit this lack of validation to gain unauthorized access to internal network resources. This vulnerability was tracked as ZDI-CAN-26415. Users are advised to upgrade to RouterOS 7.20 or any later version to mitigate this vulnerability. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall to limit exposure from untrusted networks, including traffic to services or tunnel endpoints that should be reachable only from trusted peers.

CVE-2025-6443
RouterOS
Jun 25, 2025
High7.5MikroTik

High [CVE-2024-54952] RouterOS: MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability.

A memory corruption vulnerability has been discovered in the SMB service of MikroTik RouterOS. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets to the SMB service, triggering a null pointer dereference. This results in a remote denial of service (DoS) condition, rendering the SMB service unavailable. Users are advised to upgrade to the latest RouterOS 7.x stable release to address this vulnerability. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so SMB and other device services are not reachable from untrusted networks.

CVE-2024-54952
RouterOS
May 29, 2025
Medium5.4MikroTik

Medium [CVE-2024-54772] MikroTik RouterOS: Issue Summary A vulnerability has been identified in the WinBox service, where a discrepancy in response size between connection…

Issue Summary A vulnerability has been identified in the WinBox service, where a discrepancy in response size between connection attempts with valid and invalid usernames allows attackers to confirm if user accounts exists via brute forcing the login process. In other words, when attacker tries to log into the device, by examining the response, the attacker can deduce if such a user exists on the device. Even if username is found, password still needs to be guessed as well. Affected Versions RouterOS versions prior to 6.49.18 and 7.18. Recommended Actions Update RouterOS – Upgrade to 6.49.18, 7.18, or a newer version to patch the vulnerability. Monitor for unusual login attempts – Review router logs for suspicious authentication activity and take action accordingly. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so WinBox and other management services are not reachable from untrusted networks. Mitigation strategies for devices that cannot be updated immediately Restrict WinBox Access. Firewall the WinBox port on public interfaces and untrusted networks. Affected products named by the advisory: MikroTik RouterOS.

CVE-2024-54772
RouterOSWinbox / The Dude
Feb 11, 2025
High7.5MikroTik

High [CVE-2023-32154] RouterOS: Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability.

On 10/05/2023 (May 10th, 2023) MikroTik received information about a new vulnerability, which is assigned the ID CVE-2023-32154. The report stated, that vendor (MikroTik) was contacted in December, but we did not find record of such communication. The original report also says, that vendor was informed in person in an event in Toronto, where MikroTik was not present in any capacity. What this issue affects: The issue affects devices running MikroTik RouterOS versions v6.xx and v7.xx with enabled IPv6 advertisement receiver functionality. You are only affected if one of the below settings is applied: ipv6/settings/ set accept-router-advertisements=yes or ipv6/settings/set forward=no accept-router-advertisements=yes-if-forwarding-disabled If the above settings are not set up like in the example, you are not affected. Note that the vulnerable setting combination is not normally found in routers and is rarely used. What this issue can cause: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability.

CVE-2023-32154
RouterOS
May 3, 2024
Medium5.3MikroTik

Medium [CVE-2023-41570] RouterOS: MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.

MikroTik RouterOS versions 7.1 through 7.11 contained an access control issue in the REST API. The issue applied to installations where the REST API was enabled and reachable, and could allow requests to be handled with incorrect access control. This issue is fixed in RouterOS 7.12 and newer releases. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so API and management services are available only from trusted networks.

CVE-2023-41570
RouterOS
Nov 14, 2023
High7.5MikroTik

High [CVE-2023-30800] RouterOS: The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue.

The web server used by MikroTik RouterOS version 6 was affected by a heap memory corruption issue. In specific conditions, a crafted HTTP request could cause the web interface service to crash and restart. This affected the availability of the web interface, while the service restarted automatically. This issue is fixed in RouterOS 6.49.10 stable. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so web and management services are not reachable from untrusted networks.

CVE-2023-30800
RouterOS
Sep 7, 2023
Critical9.1MikroTik

Critical [CVE-2023-30799] RouterOS: MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue.

A new CVE has been published, which describes a policy elevation issue, where a logged in administrator with “policy” permissions (able to grant additional permissions to any user on the router), is also able to send crafted configuration commands, that are exchanged internally by the router software components and normally are rejected when sent by a user. This can be used as a stepping stone to execute arbitrary code on the router, allowing the connected user to gain control of the underlying operating system upon which RouterOS runs. To be able to use this discovered exploit, one would need administrative access to RouterOS, i.e. a known username and password, as well as a ways to connect (no firewall). This is not the only way how a logged in administrator user with such a high access level (as required for this exploit) can compromise the router. Other possibilities include: saving, modifying and restoring configuration backup; installing additional software packages; using another device on the local network to perform network reinstall of the router to a known vulnerable version. Affected product named by the advisory: MikroTik RouterOS.

CVE-2023-30799
RouterOS
Jul 19, 2023

← All MikroTik advisories