Vulnerabilities (CVE)

Filtered by vendor Mikrotik Subscribe
Filtered by product Routeros
Total 84 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-20149 1 Mikrotik 1 Routeros 2026-06-17 N/A 9.8 CRITICAL
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later.
CVE-2015-2350 1 Mikrotik 1 Routeros 2026-06-17 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request in the status page to /cfg.
CVE-2012-6050 1 Mikrotik 1 Routeros 2026-06-16 6.4 MEDIUM N/A
The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request to download the router's DLLs or plugins, as demonstrated by roteros.dll.
CVE-2008-6976 1 Mikrotik 1 Routeros 2026-06-16 6.4 MEDIUM N/A
MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.