Skip to content
COOEY

FAIL › dossier

MikroTik

VENDOR

· dossier confidence 20%

MikroTik provides RouterOS for network infrastructure but has demonstrated significant security weaknesses through multiple high-severity vulnerabilities in RouterOS, including remote code execution and directory traversal flaws that require active patching and user vigilance.

PROFILE
CategorynetworkingWhat they doMikroTik develops RouterOS, a network operating system for routers and switches. Websitehttps://mikrotik.com ↗
SECURITY POSTURE

MikroTik has a history of high-severity vulnerabilities in RouterOS, including directory traversal and remote code execution flaws, indicating gaps in secure development and patching cycles.

Notable failures
  • CVE-2018-14847: directory traversal RCE in WinBox
  • CVE-2018-7445: remote code execution in RouterOS
Patterns: unpatched edge-device RCEs; directory traversal in management interfaces
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2021-12-01 CVE-2018-14847 high MikroTik RouterOS 6.42 allows unauthenticated remote attackers to read arbitrary files and authenticated attackers to write arbitrary files via directory traversal in the WinBox interface.
2022-09-08 CVE-2018-7445 high MikroTik RouterOS CVE-2018-7445 exploited for code execution
Open questions: MikroTik's current patching SLA · MikroTik's security certification status
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-29 04:13:22.178316+00:00