Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mikrotik

First CVE: Aug 19, 2009Active for: 17 yearsTotal CVEs: 89
54.1
VTI Score
TOP TARGET

Mikrotik manufactures network routing and switching appliances that range from commodity edge routers to high-end carrier-class equipment, alongside its Winbox management interface, and sits as a prominent target in the vulnerability landscape despite a relatively narrow product portfolio. Vulnerabilities affecting the vendor reach moderate severity levels, while the exposure frequently acquires public exploit code, reflecting the appeal of internet-facing routing infrastructure to attackers seeking device compromise and network pivoting. The recurring weakness classes—including out-of-bounds writes, NULL-pointer dereferences, uncontrolled resource consumption, path traversal, and reachable assertions—cluster around input parsing and resource management in the RouterOS kernel and administrative interface, areas inherent to low-level network software handling untrusted traffic. Defenders should prioritize patching Mikrotik appliances exposed to the internet and inventory RouterOS deployments as a critical infrastructure asset; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
89
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
2.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Mikrotik over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2009
16 years ago
Most Recent CVE
May 5, 2026
80 days ago

Products(31 total)

Top CVEs

Signals from CVEs in this vendor scope (89 CVEs).

89 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-14847CRITICAL
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traver
Aug 2, 20189.198YESYES
CVE-2018-7445CRITICAL
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vuln
Mar 19, 20189.895YESYES
CVE-2017-7285HIGH
A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP R
Mar 29, 20177.545NOYES
CVE-2019-3924HIGH
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defined network requests to both WA
Feb 20, 20197.544NOYES
CVE-2018-10070HIGH
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on por
Apr 16, 20187.541NOYES
CVE-2019-3978HIGH
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a
Oct 29, 20197.540NOYES
CVE-2017-17538HIGH
MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.
Dec 13, 20177.534NOYES
CVE-2017-6444HIGH
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a den
Mar 12, 20177.534NOYES
CVE-2012-6050MEDIUM
The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other im
Nov 27, 20126.434NOYES
CVE-2021-41987HIGH
In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the sc
Mar 16, 20228.133NONO
View all 89 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products89 CVEs
58%
35%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.1%)
Network83 (93.3%)
Unknown3 (3.4%)
Physical0 (0.0%)
Adjacent Network1 (1.1%)
Attack Complexity
Low79 (88.8%)
High7 (7.9%)
Unknown3 (3.4%)
User Interaction
None84 (94.4%)
Unknown3 (3.4%)
Required1 (1.1%)
Privileges Required
Low49 (55.1%)
High1 (1.1%)
None36 (40.4%)
Unknown3 (3.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (89 CVEs).

CISA KEV
2 CVEs
2.2% of CVEs· 99th percentile
Metasploit
1 CVE
1.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
12.4% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mikrotik.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mikrotik — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mikrotik's Products

View all 6 CNAs →

Top CWEs