Vulnerabilities > Mikrotik > Routeros

DATE CVE VULNERABILITY TITLE RISK
2019-02-20 CVE-2019-3924 Confused Deputy vulnerability in Mikrotik Routeros
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability.
network
low complexity
mikrotik CWE-441
5.0
2018-08-23 CVE-2018-1159 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mikrotik Routeros
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory corruption vulnerability.
network
low complexity
mikrotik CWE-119
4.0
2018-08-23 CVE-2018-1158 Uncontrolled Recursion vulnerability in Mikrotik Routeros
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a stack exhaustion vulnerability.
network
low complexity
mikrotik CWE-674
4.0
2018-08-23 CVE-2018-1157 Resource Exhaustion vulnerability in Mikrotik Routeros
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory exhaustion vulnerability.
network
low complexity
mikrotik CWE-400
6.8
2018-08-23 CVE-2018-1156 Out-of-bounds Write vulnerability in Mikrotik Routeros
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to stack buffer overflow through the license upgrade interface.
network
low complexity
mikrotik CWE-787
critical
9.0
2018-08-02 CVE-2018-14847 Path Traversal vulnerability in Mikrotik Routeros
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
network
low complexity
mikrotik CWE-22
6.4
2018-04-13 CVE-2018-10066 Improper Certificate Validation vulnerability in Mikrotik Routeros 6.41.4
An issue was discovered in MikroTik RouterOS 6.41.4.
network
mikrotik CWE-295
6.8
2018-03-19 CVE-2018-7445 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mikrotik Routeros
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.
network
low complexity
mikrotik CWE-119
critical
10.0
2017-05-18 CVE-2017-8338 Resource Exhaustion vulnerability in Mikrotik Routeros 6.38.5
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all devices will be disconnected from the router and all logs removed automatically.
network
low complexity
mikrotik CWE-400
7.8
2017-03-29 CVE-2017-7285 Resource Exhaustion vulnerability in Mikrotik Routeros 6.38.5
A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP connections.
network
low complexity
mikrotik CWE-400
7.8