Skip to content
VulniPulse

MikroTik RouterOS Vulnerabilities & Security Advisories

10 advisories tracked · MikroTik Security Announcements + NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published MikroTik advisory that VulniPulse classified as RouterOS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 6 high, 2 medium.

Android app · Google Play

Monitor MikroTik CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

MikroTik Security Announcements + NVD

MikroTik publishes official security announcements at mikrotik.com/supportsec, but has no machine-readable feed and its CVEs are assigned by several CNAs. VulniPulse joins NVD candidate metadata to the server-rendered official announcement index, then releases an alert only after fetching the linked article and verifying its CVE identity in the article heading or body. Covers RouterOS (v6/v7), SwOS, Winbox, The Dude and MikroTik router/switch hardware (hEX, CCR, CRS, cAP, wAP).

Latest MikroTik RouterOS advisories

Medium5.4MikroTik

Medium [CVE-2024-54772] MikroTik RouterOS: Issue Summary A vulnerability has been identified in the WinBox service, where a discrepancy in response size between connection…

Issue Summary A vulnerability has been identified in the WinBox service, where a discrepancy in response size between connection attempts with valid and invalid usernames allows attackers to confirm if user accounts exists via brute forcing the login process. In other words, when attacker tries to log into the device, by examining the response, the attacker can deduce if such a user exists on the device. Even if username is found, password still needs to be guessed as well. Affected Versions RouterOS versions prior to 6.49.18 and 7.18. Recommended Actions Update RouterOS – Upgrade to 6.49.18, 7.18, or a newer version to patch the vulnerability. Monitor for unusual login attempts – Review router logs for suspicious authentication activity and take action accordingly. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so WinBox and other management services are not reachable from untrusted networks. Mitigation strategies for devices that cannot be updated immediately Restrict WinBox Access. Firewall the WinBox port on public interfaces and untrusted networks. Affected products named by the advisory: MikroTik RouterOS.

CVE-2024-54772
RouterOSWinbox / The Dude
Feb 11, 2025
Medium5.3MikroTik

Medium [CVE-2023-41570] RouterOS: MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.

MikroTik RouterOS versions 7.1 through 7.11 contained an access control issue in the REST API. The issue applied to installations where the REST API was enabled and reachable, and could allow requests to be handled with incorrect access control. This issue is fixed in RouterOS 7.12 and newer releases. MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so API and management services are available only from trusted networks.

CVE-2023-41570
RouterOS
Nov 14, 2023

← All MikroTik advisories