MikroTik Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for MikroTik products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

3

In CISA KEV

2

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

MikroTik KEVs Added by Year

Loading...

3 MikroTik KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2017-20149

The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and...

High Not in CISA 15 Oct 2022
CVE-2018-14847

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write...

Confirmed In CISA 01 Dec 2021
CVE-2018-7445

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to...

Confirmed In CISA 08 Sep 2022

Common Vulnerability Classes (CWE)

  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 1
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-787 — Out-of-bounds Write 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology