CVE-2024-27686
Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.
All CVEs associated with "MikroTik RouterOS". Page 1/1 • 14 CVEs.
A curated feed of “MikroTik RouterOS”-related CVEs appears below. We currently track 14 CVEs for this tag (all time). In the last 365 days, 7 were published. Average CVSS is 6.9 (all time; 7.3 over 365d), and 36% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer, CWE-400 - Uncontrolled Resource Consumption, CWE-295 - Improper Certificate Validation.
In our taxonomy this topic maps to a LOW impact class. Network and security appliances sit on critical paths. Restrict management exposure, back up configs, and schedule firmware updates with policy validation. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | EOL | LTS |
|---|---|---|---|---|
| 7.22 | 7.22.3 | - | ||
| 7.21 | 7.21.4 | - | LTS | |
| 7.20 | 7.20.8 | Expired | LTS | |
| 7.19 | 7.19.6 | Expired | ||
| 7.18 | 7.18.2 | Expired | ||
| 7.17 | 7.17.2 | Expired | ||
| 7.16 | 7.16.2 | Expired | ||
| 7.15 | 7.15.3 | Expired | ||
| 7.14 | 7.14.3 | Expired | ||
| 7.13 | 7.13.5 | Expired | ||
| 7.12 | 7.12.2 | Expired | ||
| 7.11 | 7.11.3 | Expired | ||
| 7.10 | 7.10.2 | Expired | ||
| 7.9 | 7.9.2 | Expired | ||
| 7.8 | 7.8 | Expired | ||
| 7.7 | 7.7 | Expired | ||
| 7.6 | 7.6 | Expired | ||
| 7.5 | 7.5 | Expired | ||
| 7.4 | 7.4.1 | Expired | ||
| 7.3 | 7.3.1 | Expired | ||
| 7.2 | 7.2.3 | Expired | ||
| 7.1 | 7.1.5 | Expired | ||
| 6.49 | 6.49.19 | Expired | LTS | |
| 6.48 | 6.48.7 | - Expired | ||
| 6.47 | 6.47.10 | - Expired | ||
| 6.46 | 6.46.8 | - Expired | LTS | |
| 6.45 | 6.45.9 | - Expired | LTS | |
| 6.44 | 6.44.6 | - Expired | LTS | |
| 6.43 | 6.43.16 | - Expired | LTS | |
| 6.42 | 6.42.12 | - Expired | LTS | |
| 6.41 | 6.41.4 | - Expired | ||
| 6.40 | 6.40.9 | - Expired | LTS | |
| 6.39 | 6.39.3 | - Expired | LTS | |
| 6.38 | 6.38.7 | - Expired | LTS | |
| 6.37 | 6.37.5 | - Expired | LTS | |
| 6.36 | 6.36.3 | - Expired | ||
| 6.35 | 6.35.4 | - Expired | ||
| 6.34 | 6.34.6 | - Expired | LTS | |
| 6.33 | 6.33.6 | - Expired | ||
| 6.32 | 6.32.4 | - Expired | LTS | |
| 6.30 | 6.30.4 | - Expired | LTS | |
| 6.29 | 6.29.1 | - Expired | ||
| 6.28 | 6.28 | - Expired | ||
| 6.27 | 6.27 | - Expired | ||
| 6.26 | 6.26 | - Expired | ||
| 6.25 | 6.25 | - Expired | ||
| 6.24 | 6.24 | - Expired | ||
| 6.23 | 6.23 | - Expired | ||
| 6.22 | 6.22 | - Expired | ||
| 6.20 | 6.21.1 | - Expired | ||
| 6.19 | 6.19 | - Expired | ||
| 6.18 | 6.18 | - Expired | ||
| 6.17 | 6.17 | - Expired | ||
| 6.16 | 6.16 | - Expired | ||
| 6.15 | 6.15 | - Expired | ||
| 6.14 | 6.14 | - Expired | ||
| 6.13 | 6.13 | - Expired | ||
| 6.12 | 6.12 | - Expired | ||
| 6.11 | 6.11 | - Expired | ||
| 6.10 | 6.10 | - Expired | ||
| 6.9 | 6.9 | - Expired | ||
| 6.7 | 6.7 | - Expired | ||
| 6.6 | 6.6 | - Expired | ||
| 6.5 | 6.5 | - Expired | ||
| 6.4 | 6.4 | - Expired | ||
| 5.26 | 5.26 | - Expired | ||
| 6.3 | 6.3 | - Expired | ||
| 6.2 | 6.2 | - Expired | ||
| 6.1 | 6.1 | - Expired | ||
| 6.0 | 6.0 | - Expired | ||
| 5.25 | 5.25 | - Expired | ||
| 5.24 | 5.24 | - Expired | ||
| 5.23 | 5.23 | - Expired | ||
| 5.22 | 5.22 | - Expired | ||
| 5.21 | 5.21 | - Expired | ||
| 5.20 | 5.20 | - Expired | ||
| 5.19 | 5.19 | - Expired | ||
| 5.18 | 5.18 | - Expired | ||
| 5.17 | 5.17 | - Expired | ||
| 5.16 | 5.16 | - Expired | ||
| 5.14 | 5.14 | - Expired | ||
| 5.13 | 5.13 | - Expired | ||
| 5.12 | 5.12 | - Expired | ||
| 5.11 | 5.11 | - Expired | ||
| 5.9 | 5.9 | - Expired | ||
| 5.8 | 5.8 | - Expired | ||
| 5.7 | 5.7 | - Expired | ||
| 4.17 | 4.17 | - Expired | ||
| 4.10 | 4.10 | - Expired | ||
| 3.30 | 3.30 | - Expired |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “MikroTik RouterOS” · RSS (High+Critical only)
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.
RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x…
A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulatio…
An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the admin…
A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip/address/print of the component libjson.so. The manipulation leads to buffer ov…
A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victi…
A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets.
An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A…
Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated attackers to execute arbitrary code via a crafted pac…
The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain…
Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator…
The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request…
MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.
SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request.