Vulnerabilities > Mikrotik > Routeros > 6.25

DATE CVE VULNERABILITY TITLE RISK
2018-08-23 CVE-2018-1157 Resource Exhaustion vulnerability in Mikrotik Routeros
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory exhaustion vulnerability.
network
low complexity
mikrotik CWE-400
6.8
2018-08-23 CVE-2018-1156 Out-of-bounds Write vulnerability in Mikrotik Routeros
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to stack buffer overflow through the license upgrade interface.
network
low complexity
mikrotik CWE-787
critical
9.0
2018-08-02 CVE-2018-14847 Path Traversal vulnerability in Mikrotik Routeros
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
network
low complexity
mikrotik CWE-22
6.4
2018-03-19 CVE-2018-7445 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mikrotik Routeros
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.
network
low complexity
mikrotik CWE-119
critical
10.0
2017-03-12 CVE-2017-6444 Resource Exhaustion vulnerability in Mikrotik Routeros 6.25
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets.
network
low complexity
mikrotik CWE-400
7.8