Mikrotik manufactures network routing and switching appliances that range from commodity edge routers to high-end carrier-class equipment, alongside its Winbox management interface, and sits as a prominent target in the vulnerability landscape despite a relatively narrow product portfolio. Vulnerabilities affecting the vendor reach moderate severity levels, while the exposure frequently acquires public exploit code, reflecting the appeal of internet-facing routing infrastructure to attackers seeking device compromise and network pivoting. The recurring weakness classes—including out-of-bounds writes, NULL-pointer dereferences, uncontrolled resource consumption, path traversal, and reachable assertions—cluster around input parsing and resource management in the RouterOS kernel and administrative interface, areas inherent to low-level network software handling untrusted traffic. Defenders should prioritize patching Mikrotik appliances exposed to the internet and inventory RouterOS deployments as a critical infrastructure asset; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mikrotik over time
Signals from CVEs in this vendor scope (89 CVEs).
89 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14847CRITICAL MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traver | Aug 2, 2018 | 9.1 | 98 | YES | YES |
CVE-2018-7445CRITICAL A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vuln | Mar 19, 2018 | 9.8 | 95 | YES | YES |
CVE-2017-7285HIGH A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP R | Mar 29, 2017 | 7.5 | 45 | NO | YES |
CVE-2019-3924HIGH MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defined network requests to both WA | Feb 20, 2019 | 7.5 | 44 | NO | YES |
CVE-2018-10070HIGH A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on por | Apr 16, 2018 | 7.5 | 41 | NO | YES |
CVE-2019-3978HIGH RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a | Oct 29, 2019 | 7.5 | 40 | NO | YES |
CVE-2017-17538HIGH MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets. | Dec 13, 2017 | 7.5 | 34 | NO | YES |
CVE-2017-6444HIGH The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a den | Mar 12, 2017 | 7.5 | 34 | NO | YES |
CVE-2012-6050MEDIUM The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other im | Nov 27, 2012 | 6.4 | 34 | NO | YES |
CVE-2021-41987HIGH In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the sc | Mar 16, 2022 | 8.1 | 33 | NO | NO |
Signals from CVEs in this vendor scope (89 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mikrotik.
Media articles that mention a CVE ID that affects a product developed by Mikrotik — matched by CVE ID, not by vendor name.