The web server used by MikroTik RouterOS version 6 is...
High severity
Unreviewed
Published
Sep 7, 2023
to the GitHub Advisory Database
•
Updated Nov 21, 2025
Description
Published by the National Vulnerability Database
Sep 7, 2023
Published to the GitHub Advisory Database
Sep 7, 2023
Last updated
Nov 21, 2025
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.
References