Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.95% | — | Mikrotik RouterosAI | 2/10/2026 | 6/10/2026 | The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single… | |
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Mikrotik RouterosAI | 22/9/2026 | 25/9/2026 | MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum… | |
| Pendiente de análisis | Media (4.6) | 0.16% | — | MikrotikAI | 16/9/2026 | 22/9/2026 | MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authenticating to the device and without knowledge of the administrative password. | |
| Pendiente de análisis | Alta (8.2) | 0.58% | — | Mikrotik RouterosAI | 16/9/2026 | 24/9/2026 | MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that… | |
| Pendiente de análisis | Media (6.3) | 0.39% | — | Mikrotik RouterosAI | 16/9/2026 | 24/9/2026 | MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the… | |
| Pendiente de análisis | Media (6.9) | 0.38% | — | Mikrotik RouterosAI | 14/9/2026 | 24/9/2026 | MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path… | |
| Pendiente de análisis | Media (5.3) | 0.49% | — | Mikrotik RouterosAI | 14/9/2026 | 24/9/2026 | MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to the /tool fetch command; the first write… | |
| Analizada | Crítica (9.2) | 6.4% | ⚠ Explotación activa | Mikrotik Routeros | 5/9/2026 | 11/9/2026 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue… | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa | Mikrotik Routeros | 5/9/2026 | 11/9/2026 | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted… | |
| Analizada | Alta (8.7) | 0.73% | — | Mikrotik Routeros | 5/9/2026 | 25/9/2026 | RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with… | |
| Analizada | Media (6.9) | 1.0% | ⚠ Explotación activa | Mikrotik Routeros | 5/9/2026 | 26/9/2026 | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and… | |
| Analizada | Media (6.3) | 0.25% | — | Mikrotik Routeros | 5/9/2026 | 25/9/2026 | MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public… | |
| Analizada | Crítica (9.2) | 6.5% | — | Mikrotik Routeros | 5/9/2026 | 25/9/2026 | RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with… | |
| Aplazada | Media (6.9) | 0.38% | — | Mikrotik RouterosAI | 30/7/2026 | 8/9/2026 | An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose… | |
| Aplazada | Alta (8.7) | 0.39% | — | Mikrotik RouterosAI | 28/7/2026 | 30/7/2026 | MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive… | |
| Aplazada | Alta (7.5) | 0.58% | — | Mikrotik RouterosAI | 13/7/2026 | 15/7/2026 | An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so. | |
| Pendiente de análisis | Alta (7.5) | 0.59% | — | Mikrotik RouterosAI | 8/5/2026 | 17/6/2026 | Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445. | |
| Pendiente de análisis | Media (6.5) | 0.19% | — | Mikrotik RouterosAIOpenvpnAIMikrotik CapsmanAI | 5/5/2026 | 30/9/2026 | RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerability lies in shared certificate validation logic which uses the system certificate… | |
| Aplazada | Media (5.5) | 0.50% | — | Mikrotik RouterosAI | 2/5/2026 | 17/6/2026 | A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The… | |
| Aplazada | Crítica (10) | 0.30% | — | Mikrotik RouterosAIMikrotik SwosAI | 27/10/2025 | 17/6/2026 | An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials. | |
| Aplazada | Alta (7.4) | 0.77% | — | Mikrotik RouterosAI | 25/9/2025 | 17/6/2026 | A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.… | |
| Aplazada | Media (4.8) | 0.72% | — | Mikrotik RouterosAI | 3/7/2025 | 17/6/2026 | A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victim browses to the malicious URL and logs in, the XSS executes. The POST request used to login, can also be converted to a… | |
| Aplazada | Media (6.5) | 0.24% | — | Mikrotik RouterosAI | 30/6/2025 | 5/7/2026 | A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets. | |
| Analizada | Alta (7.2) | 0.57% | — | Mikrotik Routeros | 25/6/2025 | 17/6/2026 | Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of remote IP… | |
| Analizada | Alta (7.5) | 0.55% | — | Mikrotik Routeros | 29/5/2025 | 17/6/2026 | MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Service (DoS), rendering the SMB service unavailable. |