MikroTik / Routeros
84 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-93345 | MikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-VPN NLRI | HIGH | 8.7 | Sep 22, 2026 |
| CVE-2026-89028 | MikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndX | HIGH | 8.2 | Sep 16, 2026 |
| CVE-2026-56719 | MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX | MEDIUM | 6.3 | Sep 16, 2026 |
| CVE-2026-89021 | MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction | MEDIUM | 6.9 | Sep 14, 2026 |
| CVE-2026-89020 | MikroTik RouterOS Stack Buffer Overflow via TFTP URL Path | MEDIUM | 5.3 | Sep 14, 2026 |
| CVE-2026-86060 KEV | SSH session privilege manipulation via a crafted username in Mikrotik RouterOS | CRITICAL | 9.2 | Sep 5, 2026 |
| CVE-2026-67281 | Unauthenticated file read in Mikrotik RouterOS | HIGH | 8.7 | Sep 5, 2026 |
| CVE-2026-67279 KEV | SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS | MEDIUM | 6.9 | Sep 5, 2026 |
| CVE-2026-67278 | TLS server impersonation possible in Mikrotik RouterOS | MEDIUM | 6.3 | Sep 5, 2026 |
| CVE-2026-67277 KEV | Kernel memory disclosure and denial of service in MikroTik RouterOS btest service | HIGH | 8.8 | Sep 5, 2026 |
| CVE-2026-67276 | SSH user impersonation possible in Mikrotik RouterOS | CRITICAL | 9.2 | Sep 5, 2026 |
| CVE-2026-14227 | Insufficient session expiration in MikroTik RouterOS | MEDIUM | 6.9 | Jul 30, 2026 |
| CVE-2026-16347 | Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router | HIGH | 8.7 | Jul 28, 2026 |
| CVE-2025-42611 | Improper certificate validation in multiple RouterOS services | MEDIUM | 6.5 | May 5, 2026 |
| CVE-2026-7668 | MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds | MEDIUM | 6.9 | May 2, 2026 |
| CVE-2025-10948 | MikroTik RouterOS libjson.so print parse_json_element buffer overflow | HIGH | 8.7 | Sep 25, 2025 |
| CVE-2025-6563 | Cross-site scripting via dst parameter in RouterOS WiFi hotspot | MEDIUM | 4.8 | Jul 3, 2025 |
| CVE-2025-6443 | Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability | HIGH | 7.2 | Jun 25, 2025 |
| CVE-2024-54952 | MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending speci… | HIGH | 7.5 | May 29, 2025 |
| CVE-2024-54772 | An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is ava… | MEDIUM | 5.4 | Feb 11, 2025 |
| CVE-2023-32154 | Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability | HIGH | 7.5 | May 3, 2024 |
| CVE-2023-41570 | MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API. | MEDIUM | 5.3 | Nov 14, 2023 |
| CVE-2023-30800 | MikroTik RouterOS Web Interface Heap Corruption | HIGH | 7.5 | Sep 7, 2023 |
| CVE-2023-30799 | MikroTik RouterOS Administrator Privilege Escalation | CRITICAL | 9.1 | Jul 19, 2023 |
| CVE-2020-20021 | An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon. | HIGH | 7.5 | Jul 12, 2023 |
Showing 1 to 25 of 84 CVEs