<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – MikroTik RouterOS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/routeros.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/routeros-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – MikroTik RouterOS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-27686 – Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27686</guid>
    <pubDate>Fri, 08 May 2026 06:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27686</strong></p>
  <p>Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7668 – A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7668</guid>
    <pubDate>Sat, 02 May 2026 21:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7668</strong></p>
  <p>A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The exploit is publicly available and might be used. You should upgrade the affected comp…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-61481 – An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig manage...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61481</guid>
    <pubDate>Mon, 27 Oct 2025 14:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-61481</strong></p>
  <p>An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10948 – A vulnerability has been found in MikroTik RouterOS 7. This affects the function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10948</guid>
    <pubDate>Thu, 25 Sep 2025 14:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10948</strong></p>
  <p>A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.20.1 and 7.21beta2 mitigates this issue. You should upgr…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-0680 – SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-0680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-0680</guid>
    <pubDate>Tue, 12 Feb 2008 01:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-0680</strong></p>
  <p>SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-0680">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
