Skip to content
VulniPulse

MikroTik RouterOS Vulnerabilities & Security Advisories

10 advisories tracked · MikroTik Security Announcements + NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published MikroTik advisory that VulniPulse classified as RouterOS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 6 high, 2 medium.

Android app · Google Play

Monitor MikroTik CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

MikroTik Security Announcements + NVD

MikroTik publishes official security announcements at mikrotik.com/supportsec, but has no machine-readable feed and its CVEs are assigned by several CNAs. VulniPulse joins NVD candidate metadata to the server-rendered official announcement index, then releases an alert only after fetching the linked article and verifying its CVE identity in the article heading or body. Covers RouterOS (v6/v7), SwOS, Winbox, The Dude and MikroTik router/switch hardware (hEX, CCR, CRS, cAP, wAP).

Latest MikroTik RouterOS advisories

High7.5MikroTik

High [CVE-2024-27686] Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash)

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

CVE-2024-27686
RouterOS
May 8, 2026
High8.8MikroTik

High [CVE-2025-10948] RouterOS: vulnerability has been found in MikroTik RouterOS 7.

A buffer overflow vulnerability has been discovered in MikroTik RouterOS 7, affecting the parse_json_element function within the libjson.so component. The vulnerability is triggered through the /rest/ip/address/print endpoint and can be exploited remotely. The exploit for this issue has been publicly disclosed and may be actively used. Upgrading to RouterOS version 7.20.1 or 7.21beta2 mitigates this issue. The vendor has confirmed that a fix has been implemented and plans to release a RouterOS update containing the patch. Users should upgrade to the latest available version to ensure full protection. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so REST API and management services are available only from trusted networks.

CVE-2025-10948
RouterOS
Sep 25, 2025
High7.2MikroTik

High [CVE-2025-6443] RouterOS: Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability.

An improper access control vulnerability has been identified in MikroTik RouterOS, related to the handling of VXLAN source IP addresses. This flaw allows remote attackers to bypass access restrictions on affected installations without requiring authentication. The specific issue exists within the processing of remote IP addresses during VXLAN traffic handling. The router fails to validate the remote IP address against configured values before allowing ingress traffic into the internal network. An attacker can exploit this lack of validation to gain unauthorized access to internal network resources. This vulnerability was tracked as ZDI-CAN-26415. Users are advised to upgrade to RouterOS 7.20 or any later version to mitigate this vulnerability. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall to limit exposure from untrusted networks, including traffic to services or tunnel endpoints that should be reachable only from trusted peers.

CVE-2025-6443
RouterOS
Jun 25, 2025
High7.5MikroTik

High [CVE-2024-54952] RouterOS: MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability.

A memory corruption vulnerability has been discovered in the SMB service of MikroTik RouterOS. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets to the SMB service, triggering a null pointer dereference. This results in a remote denial of service (DoS) condition, rendering the SMB service unavailable. Users are advised to upgrade to the latest RouterOS 7.x stable release to address this vulnerability. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so SMB and other device services are not reachable from untrusted networks.

CVE-2024-54952
RouterOS
May 29, 2025
High7.5MikroTik

High [CVE-2023-32154] RouterOS: Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability.

On 10/05/2023 (May 10th, 2023) MikroTik received information about a new vulnerability, which is assigned the ID CVE-2023-32154. The report stated, that vendor (MikroTik) was contacted in December, but we did not find record of such communication. The original report also says, that vendor was informed in person in an event in Toronto, where MikroTik was not present in any capacity. What this issue affects: The issue affects devices running MikroTik RouterOS versions v6.xx and v7.xx with enabled IPv6 advertisement receiver functionality. You are only affected if one of the below settings is applied: ipv6/settings/ set accept-router-advertisements=yes or ipv6/settings/set forward=no accept-router-advertisements=yes-if-forwarding-disabled If the above settings are not set up like in the example, you are not affected. Note that the vulnerable setting combination is not normally found in routers and is rarely used. What this issue can cause: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability.

CVE-2023-32154
RouterOS
May 3, 2024
High7.5MikroTik

High [CVE-2023-30800] RouterOS: The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue.

The web server used by MikroTik RouterOS version 6 was affected by a heap memory corruption issue. In specific conditions, a crafted HTTP request could cause the web interface service to crash and restart. This affected the availability of the web interface, while the service restarted automatically. This issue is fixed in RouterOS 6.49.10 stable. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so web and management services are not reachable from untrusted networks.

CVE-2023-30800
RouterOS
Sep 7, 2023

← All MikroTik advisories