MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HMikrotik Routeros
OSMikrotik≤ 6.48.76.34 – 6.49.7 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPE
Related vulnerabilities
CVE-2018-14847CRITICAL9.1⚠ KEVPL ✓same product
MikroTik RouterOS — path traversal w interfejsie WinBox (odczyt/zapis plików)
CVE-2018-7445CRITICAL9.8⚠ KEVPL ✓same product
MikroTik RouterOS SMB — buffer overflow przed uwierzytelnieniem (RCE)
CVE-2017-20149CRITICAL9.8PL ✓same product
MikroTik RouterOS — RCE przez uszkodzenie pamięci w serwerze WWW (Chimay-Red)
CVE-2022-34960CRITICAL9.8PL ✓same product
MikroTik RouterOS: path traversal przez symlinki w pakiecie container
CVE-2025-6443HIGH7.2same product
Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote atta...