Vulnerabilities in MikroTik

24 results
Vexday analysis

MikroTik apresenta 8 vulnerabilidades catalogadas na base, com 1 crítica (CVSS), mas nenhuma sob ataque ativo conhecido até o momento. A fraqueza predominante é CWE-119 (Buffer Overflow), um vetor clássico e de alto potencial exploratório; apenas 1 CVE foi publicado nos últimos 90 dias, indicando risco recente contido. O perfil sugere vigilância moderada, com priorização das críticas e do monitoramento de possíveis transições para exploração ativa.

CVE-2024-2169HIGHImplementations of UDP application protocols are susceptible to network loops and denial of serviceEPSS 5.4%CVE-2019-3943—MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authEPSS 3.7%CVE-2026-86060CRITICALSSH session privilege manipulation via a crafted username in Mikrotik RouterOSEPSS 1.8%KEVCVE-2023-30800HIGHMikroTik RouterOS Web Interface Heap CorruptionEPSS 1.7%CVE-2026-67277HIGHKernel memory disclosure and denial of service in MikroTik RouterOS btest serviceEPSS 1.6%KEVCVE-2023-30799CRITICALMikroTik RouterOS Administrator Privilege EscalationEPSS 1.4%CVE-2019-3981—MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication proEPSS 1.1%CVE-2025-10948HIGHMikroTik RouterOS libjson.so print parse_json_element buffer overflowEPSS 0.8%CVE-2026-67279MEDIUMSSH Pre-Authentication Rekey State Bypass in MikroTik RouterOSEPSS 0.7%CVE-2025-6563MEDIUMCross-site scripting via dst parameter in RouterOS WiFi hotspotEPSS 0.7%CVE-2026-67281HIGHUnauthenticated file read in Mikrotik RouterOSEPSS 0.6%CVE-2023-32154HIGHMikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-89028HIGHMikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndXEPSS 0.6%CVE-2025-6443HIGHMikrotik RouterOS VXLAN Source IP Improper Access Control VulnerabilityEPSS 0.6%CVE-2026-7668MEDIUMMikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-boundsEPSS 0.5%CVE-2026-93345HIGHMikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-VPN NLRIEPSS 0.5%CVE-2026-89020MEDIUMMikroTik RouterOS Stack Buffer Overflow via TFTP URL PathEPSS 0.5%CVE-2026-56719MEDIUMMikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndXEPSS 0.4%CVE-2026-16347HIGHImproper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted RouterEPSS 0.4%CVE-2026-89021MEDIUMMikroTik RouterOS Path Traversal via Container OCI/tar Image ExtractionEPSS 0.4%