VendorsMikrotikrouterosall versions
Vulnerabilities

Mikrotik RouterOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

84CVEs
CVE-2017-6297
The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.
Published 2017-02-27 · Modified
5.9EPSS 0.007
CVE-2024-54772
An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.
Published 2025-02-11 · Analyzed
5.4EPSS 0.008
CVE-2023-41570
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
Published 2023-11-14 · Modified
5.3EPSS 0.005
CVE-2019-3981
MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.
Published 2020-01-14 · Modified
4.3EPSS 0.011
← Prev3 / 3