CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
MikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-VPN NLRI
MikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndX
MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX
MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction
MikroTik RouterOS Stack Buffer Overflow via TFTP URL Path
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
Unauthenticated file read in Mikrotik RouterOS
SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
TLS server impersonation possible in Mikrotik RouterOS
Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
SSH user impersonation possible in Mikrotik RouterOS
Insufficient session expiration in MikroTik RouterOS
Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router
Improper certificate validation in multiple RouterOS services
MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds
MikroTik RouterOS libjson.so print parse_json_element buffer overflow
Cross-site scripting via dst parameter in RouterOS WiFi hotspot
Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability
MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending speci…
An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is ava…
Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
MikroTik RouterOS Web Interface Heap Corruption
MikroTik RouterOS Administrator Privilege Escalation
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.
Showing 1 to 25 CVEs · page 1 (more available)