- EPSS 61.02%
- Veröffentlicht 19.03.2018 21:29:01
- Zuletzt bearbeitet 07.11.2025 19:04:17
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs b...
CVE-2017-8338
- EPSS 4.21%
- Veröffentlicht 18.05.2017 06:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; a...
CVE-2017-7285
- EPSS 19.34%
- Veröffentlicht 29.03.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP conn...
CVE-2017-6444
- EPSS 13.49%
- Veröffentlicht 12.03.2017 05:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets. After th...
CVE-2017-6297
- EPSS 0.74%
- Veröffentlicht 27.02.2017 07:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitorin...
CVE-2015-2350
- EPSS 1.16%
- Veröffentlicht 19.03.2015 14:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request in the status page to /cfg.
CVE-2012-6050
- EPSS 9.41%
- Veröffentlicht 27.11.2012 04:49:26
- Zuletzt bearbeitet 16.06.2026 23:47:43
The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request to download the router's DLLs or plugins, as demon...
CVE-2008-6976
- EPSS 9.18%
- Veröffentlicht 19.08.2009 05:24:52
- Zuletzt bearbeitet 16.06.2026 23:03:21
MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.