CVE-2020-20218
- EPSS 1.96%
- Veröffentlicht 03.05.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:11:55
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable.
CVE-2021-27221
- EPSS 4.49%
- Veröffentlicht 19.03.2021 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:57:37
MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work
CVE-2021-3014
- EPSS 0.93%
- Veröffentlicht 04.01.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 06:20:45
In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.
CVE-2019-16160
- EPSS 2.57%
- Veröffentlicht 07.10.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:30:10
An integer underflow in the SMB server of MikroTik RouterOS before 6.45.5 allows remote unauthenticated attackers to crash the service.
CVE-2020-11881
- EPSS 3.78%
- Veröffentlicht 14.09.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:58:49
An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated remote attacker to crash the SMB server via modified setup-request packets, aka SUP-12964.
CVE-2020-10364
- EPSS 2.66%
- Veröffentlicht 23.03.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:09
The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of uncontrolled resource managemen...
CVE-2018-5951
- EPSS 4.31%
- Veröffentlicht 02.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:09:44
An issue was discovered in Mikrotik RouterOS. Crafting a packet that has a size of 1 byte and sending it to an IPv6 address of a RouterOS box with IP Protocol 97 will cause RouterOS to reboot imminently. All versions of RouterOS that supports EoIPv6 ...
CVE-2019-3981
- EPSS 1.14%
- Veröffentlicht 14.01.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:42:59
MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.
CVE-2019-3979
- EPSS 0.92%
- Veröffentlicht 29.10.2019 19:15:20
- Zuletzt bearbeitet 21.11.2024 04:42:59
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router adds all A records to its DNS cache even when the records are unrelated to the domain that was queried. Therefore, a remote attacke...
CVE-2019-3978
- EPSS 10.27%
- Veröffentlicht 29.10.2019 19:15:20
- Zuletzt bearbeitet 21.11.2024 04:42:59
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS responses are cached by the r...