VYPR

Routeros

by Mikrotik

CVEs (93)

  • CVE-2019-13954MedJul 26, 2019
    risk 0.43cvss 6.5epss 0.04

    Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server and in some circumstances reboot the system. Malicious code cannot be injected.

  • CVE-2018-1157MedAug 23, 2018
    risk 0.43cvss 6.5epss 0.04

    Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory exhaustion vulnerability. An authenticated remote attacker can crash the HTTP server and in some circumstances reboot the system via a crafted HTTP POST request.

  • CVE-2025-42611MedMay 5, 2026
    risk 0.42cvss 6.5epss 0.00

    RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerability lies in shared certificate…

  • CVE-2023-47310MedJun 30, 2025
    risk 0.42cvss 6.5epss 0.00

    A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets.

  • CVE-2022-45315MedDec 5, 2022
    risk 0.42cvss 6.4epss 0.01

    Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated attackers to execute arbitrary code via a crafted packet.

  • CVE-2022-36522MedAug 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2021-36614MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the tr069-client process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

  • CVE-2021-36613MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

  • CVE-2020-20262MedJul 21, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

  • CVE-2020-20221MedJul 21, 2021
    risk 0.42cvss 6.5epss 0.03

    Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

  • CVE-2020-20219MedJul 21, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

  • CVE-2020-20249MedJul 19, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenticated remote attacker can cause a Denial of Service.

  • CVE-2020-20248MedJul 19, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

  • CVE-2020-20230MedJul 19, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

  • CVE-2020-20231MedJul 14, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in the /nova/bin/detnet process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

  • CVE-2020-20252MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

  • CVE-2020-20250MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). NOTE: this is different from CVE-2020-20253 and…

  • CVE-2020-20217MedJul 8, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before 6.47 (stable tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/route process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

  • CVE-2020-20225MedJul 7, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

  • CVE-2020-20216MedJul 7, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/graphing process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).