VYPR

Routeros

by Mikrotik

CVEs (93)

  • CVE-2018-1158MedAug 23, 2018
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a stack exhaustion vulnerability. An authenticated remote attacker can crash the HTTP server via recursive parsing of JSON.

  • CVE-2021-3014MedJan 4, 2021
    risk 0.40cvss 6.1epss 0.01

    In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.

  • CVE-2017-6297MedFeb 27, 2017
    risk 0.38cvss 5.9epss 0.01

    The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the…

  • CVE-2024-54772MedFeb 11, 2025
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid…

  • CVE-2025-6563MedJul 3, 2025
    risk 0.34cvss epss 0.01

    A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victim browses to the malicious URL and logs in, the XSS executes. The POST request…

  • CVE-2023-41570MedNov 14, 2023
    risk 0.34cvss 5.3epss 0.00

    MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.

  • CVE-2026-14227MedJul 30, 2026
    risk 0.32cvss 4.9epss 0.00

    An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a…

  • CVE-2019-3981LowJan 14, 2020
    risk 0.24cvss 3.7epss 0.01

    MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.

  • CVE-2012-6050Nov 27, 2012
    risk 0.04cvss epss 0.09

    The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request to download the router's DLLs or plugins, as demonstrated by roteros.dll.

  • CVE-2008-6976Aug 19, 2009
    risk 0.04cvss epss 0.09

    MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.

  • CVE-2008-0680Feb 12, 2008
    risk 0.04cvss epss 0.07

    SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request.

  • CVE-2026-39042HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.

  • CVE-2015-2350Mar 19, 2015
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request in the status page to /cfg.

Page 5 of 5