Vulnerabilities > Mikrotik > Routeros > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-12-05 CVE-2022-45315 Out-of-bounds Read vulnerability in Mikrotik Routeros
Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process.
network
low complexity
mikrotik CWE-125
critical
9.8
2022-10-15 CVE-2017-20149 Out-of-bounds Write vulnerability in Mikrotik Routeros
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red.
network
low complexity
mikrotik CWE-787
critical
9.8
2022-08-25 CVE-2022-34960 Link Following vulnerability in Mikrotik Routeros 7.4
The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device.
network
low complexity
mikrotik CWE-59
critical
9.8
2018-08-02 CVE-2018-14847 Path Traversal vulnerability in Mikrotik Routeros
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
network
low complexity
mikrotik CWE-22
critical
9.1
2018-03-19 CVE-2018-7445 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mikrotik Routeros
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.
network
low complexity
mikrotik CWE-119
critical
9.8