VYPR

Vendor CVEs

Mikrotik

All CVEs

110 total · sorted by risk
  • CVE-2023-41570MedNov 14, 2023
    risk 0.34cvss 5.3epss 0.00

    MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.

  • CVE-2026-14227MedJul 30, 2026
    risk 0.32cvss 4.9epss 0.00

    An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a…

  • CVE-2025-56566MedSep 16, 2026
    risk 0.30cvss 4.6epss 0.00

    MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authenticating to the device and without…

  • CVE-2026-89020MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to…

  • CVE-2019-3981LowJan 14, 2020
    risk 0.24cvss 3.7epss 0.01

    MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.

  • CVE-2012-6050Nov 27, 2012
    risk 0.04cvss —epss 0.09

    The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request to download the router's DLLs or plugins, as demonstrated by roteros.dll.

  • CVE-2008-6976Aug 19, 2009
    risk 0.04cvss —epss 0.09

    MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.

  • CVE-2008-0680Feb 12, 2008
    risk 0.04cvss —epss 0.07

    SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request.

  • CVE-2026-39042HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.

  • CVE-2015-2350Mar 19, 2015
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request in the status page to /cfg.

Page 3 of 3