Mikrotik
Mikrotik Routeros: vulnerabilidades y CVE
Mikrotik Routeros tiene 103 vulnerabilidades publicadas, 18 de ellas en los últimos 12 meses. 8 son críticas y 5 figuran en el catálogo de explotación activa de CISA.
CVE103
Últimos 12 meses18
Críticas8
Explotadas activamente5
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-67279 | Media (6.9) | 1.0% | ⚠ Explotación activa | 5 sept 2026 | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On… |
| CVE-2026-86060 | Crítica (9.2) | 1.8% | ⚠ Explotación activa | 5 sept 2026 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation.… |
| CVE-2026-67277 | Alta (8.8) | 1.6% | ⚠ Explotación activa | 5 sept 2026 | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the… |
| CVE-2018-7445 | Crítica (9.8) | 61% | ⚠ Explotación activa | 19 mar 2018 | A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on… |
| CVE-2018-14847 | Crítica (9.1) | 96% | ⚠ Explotación activa | 2 ago 2018 | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-93345 | Alta (8.7) | 0.49% | — | 22 sept 2026 | MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service… |
| CVE-2026-89028 | Alta (8.2) | 0.58% | — | 16 sept 2026 | MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1… |
| CVE-2026-56719 | Media (6.3) | 0.39% | — | 16 sept 2026 | MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen… |
| CVE-2026-89021 | Media (6.9) | 0.38% | — | 14 sept 2026 | MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container… |
| CVE-2026-89020 | Media (5.3) | 0.49% | — | 14 sept 2026 | MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget… |
| CVE-2026-86060 | Crítica (9.2) | 1.8% | ⚠ Explotación activa | 5 sept 2026 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation.… |
| CVE-2026-67281 | Alta (8.7) | 0.73% | — | 5 sept 2026 | RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated… |
| CVE-2026-67279 | Media (6.9) | 1.0% | ⚠ Explotación activa | 5 sept 2026 | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On… |
| CVE-2026-67278 | Media (6.3) | 0.25% | — | 5 sept 2026 | MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an… |
| CVE-2026-67277 | Alta (8.8) | 1.6% | ⚠ Explotación activa | 5 sept 2026 | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the… |
| CVE-2026-67276 | Crítica (9.2) | 6.5% | — | 5 sept 2026 | RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification… |
| CVE-2026-14227 | Media (6.9) | 0.38% | — | 30 jul 2026 | An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission… |
| CVE-2026-16347 | Alta (8.7) | 0.39% | — | 28 jul 2026 | MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or… |
| CVE-2026-39042 | Alta (7.5) | 0.58% | — | 13 jul 2026 | An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so. |
| CVE-2024-27686 | Alta (7.5) | 0.59% | — | 8 may 2026 | Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445. |
| CVE-2025-42611 | Media (6.5) | 0.19% | — | 5 may 2026 | RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among… |
| CVE-2026-7668 | Media (5.5) | 0.50% | — | 2 may 2026 | A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument… |
| CVE-2025-61481 | Crítica (10) | 0.30% | — | 27 oct 2025 | An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser… |
| CVE-2025-10948 | Alta (7.4) | 0.78% | — | 25 sept 2025 | A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads to buffer overflow. The attack… |
| CVE-2025-6563 | Media (4.8) | 0.70% | — | 3 jul 2025 | A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victim browses to the… |
| CVE-2023-47310 | Media (6.5) | 0.22% | — | 30 jun 2025 | A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets. |
| CVE-2025-6443 | Alta (7.2) | 0.57% | — | 25 jun 2025 | Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS. Authentication is not… |
| CVE-2024-54952 | Alta (7.5) | 0.55% | — | 29 may 2025 | MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference.… |
| CVE-2024-54772 | Media (5.4) | 0.79% | — | 11 feb 2025 | An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in… |
| CVE-2023-32154 | Alta (7.5) | 0.61% | — | 3 may 2024 | Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS.… |
| CVE-2023-41570 | Media (5.3) | 0.47% | — | 14 nov 2023 | MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API. |
| CVE-2023-30800 | Alta (7.5) | 1.7% | — | 7 sept 2023 | The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a… |
| CVE-2023-30799 | Alta (7.2) | 1.4% | — | 19 jul 2023 | MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or… |
| CVE-2020-20021 | Alta (7.5) | 1.0% | — | 12 jul 2023 | An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon. |
| CVE-2023-24094 | Alta (7.5) | 0.82% | — | 27 mar 2023 | An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets. |