Show filters
86 Total Results
Displaying 1-10 of 86
Sort by:
Attacker Value
Unknown
CVE-2023-32154
Disclosure Date: May 03, 2024 (last updated September 18, 2024)
Mikrotik RouterOS RADVD Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the Router Advertisement Daemon. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root.
. Was ZDI-CAN-19797.
0
Attacker Value
Unknown
CVE-2024-2169
Disclosure Date: March 19, 2024 (last updated April 01, 2024)
Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.
0
Attacker Value
Unknown
CVE-2023-41570
Disclosure Date: November 14, 2023 (last updated November 22, 2023)
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
0
Attacker Value
Unknown
CVE-2023-30800
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.
0
Attacker Value
Unknown
CVE-2023-30799
Disclosure Date: July 19, 2023 (last updated October 08, 2023)
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
0
Attacker Value
Unknown
CVE-2020-20021
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.
0
Attacker Value
Unknown
CVE-2023-24094
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets.
0
Attacker Value
Unknown
CVE-2022-45315
Disclosure Date: December 05, 2022 (last updated October 08, 2023)
Mikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows attackers to execute arbitrary code via a crafted packet.
0
Attacker Value
Unknown
CVE-2022-45313
Disclosure Date: December 05, 2022 (last updated October 08, 2023)
Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message.
0
Attacker Value
Unknown
CVE-2017-20149
Disclosure Date: October 15, 2022 (last updated October 08, 2023)
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later.
0