Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MikroTik — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting MikroTik. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MikroTik develops network routing and wireless hardware primarily used for internet connectivity and network infrastructure management. Historically, their devices have been vulnerable to multiple remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from default configurations and unpatched services. With 11 CVEs currently on record, notable security characteristics include widespread deployment in small to medium enterprises making them attractive targets. Major incidents include the 2018 VPN hijacking attack where compromised routers were used to mine cryptocurrency, highlighting ongoing security challenges in their ecosystem.

Top products by MikroTik: RouterOS WinBox RouterOS-TFTP
CVE IDTitleCVSSSeverityPublished
CVE-2026-14227 Insufficient session expiration in MikroTik RouterOS — RouterOSCWE-613 4.9 Medium2026-07-30
CVE-2026-16347 Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router — RouterOSCWE-307 8.8 High2026-07-28
CVE-2025-42611 Improper certificate validation in multiple RouterOS services — RouterOSCWE-295 6.5 Medium2026-05-05
CVE-2026-7668 MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds — RouterOSCWE-125 7.3 High2026-05-02
CVE-2025-10948 MikroTik RouterOS libjson.so print parse_json_element buffer overflow — RouterOSCWE-120 8.8 High2025-09-25
CVE-2025-6563 Cross-site scripting via dst parameter in RouterOS WiFi hotspot — RouterOSCWE-20 6.1AIMediumAI2025-07-03
CVE-2025-6443 Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability — RouterOSCWE-284 9.8AICriticalAI2025-06-25
CVE-2023-32154 Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability — RouterOSCWE-787 8.8 -2024-05-03
CVE-2024-2169 Implementations of UDP application protocols are susceptible to network loops and denial of service — RouterOS-TFTP 7.5AIHighAI2024-03-19
CVE-2023-30800 MikroTik RouterOS Web Interface Heap Corruption — RouterOSCWE-787 7.5 High2023-09-07
CVE-2023-30799 MikroTik RouterOS Administrator Privilege Escalation — RouterOSCWE-269 9.1 Critical2023-07-19
CVE-2019-3981 MikroTik Winbox 安全漏洞 — WinBoxCWE-300 3.7 -2020-01-14
CVE-2019-3943 MikroTik RouterOS 路径遍历漏洞 — RouterOSCWE-23 8.1 -2019-04-10

This page lists every published CVE security advisory associated with MikroTik. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.