MikroTik Value Added Distributor, MikroTik Training Centre, MikroTik Toronto, MikroTik Canada

MikroTik Value Added Distributor, MikroTik Training Centre, MikroTik Toronto, MikroTik Canada

MikroTik Training Centre, Toronto, Canada MikroTik Value Added Distributor

T (647) 477-0163
Email: support@wirelessnetware.ca

Wireless Netware Technology LTD.
550 Alden Road, Unti# 210A, Markham, Ontario L3R6A8

Open in Google Maps
  • Home
  • Solutions
  • Services
  • Become a Canadian ISP
    • Business Internet
  • Partners
  • Hardware
  • Training
  • Blog
  • About
  • Contacts
MikroTikSupport
  • Home
  • Blog
  • Blog
  • MikroTik Security Advisory
Wireless Netware offers advice about MikroTik router security breach
Wednesday, 28 March 2018 / Published in Blog

MikroTik Security Advisory

 

Alert from MikroTik

We received this information from MikroTik today:

It has come to our attention that a rogue botnet is currently scanning random public IP addresses to find open Winbox (8291) and WWW (80) ports, to exploit a vulnerability in the RouterOS www server that was patched more than a year ago (in RouterOS v6.38.5, March 2017).

Since all RouterOS devices offer free upgrades with just two clicks, we urge you to upgrade your devices with the ‘Check for updates’ button – especially if you haven’t done so within the last year.

Click here for more information.

Want to ensure you’re always up-to-date with MikroTik?

It might be time to start or continue with your MikroTik certification training, so you never have to worry about whether your systems are fully updated and secure.

As the leading MikroTik trainer in North America, we offer a full range of MikroTik certification courses across the country – and our students say they not only learn a lot, but that they leave feeling inspired and excited about what they can take back to their organizations.

(Right now we have some great savings for our courses in Calgary and Vancouver – check them out!)

Tagged under: Security alert

What you can read next

Guaranteed-to-Run classes
Mikrotik expert Hani Rahrouh offers tips and tricks
Mikrotik insider secrets: Reset buttons
MikroTik RouterOS

Recent Posts

  • Load-balance using PCC in MikroTik RouterOS v 6.xx

    Introduction PCC “Per Connection Classifi...
  • Audience – a router for those who value both beauty and functionality

    Audience is a tri-band (2.4 GHz & high + lo...
  • DO NOT let the cables limit you, More Throughput over Power!

    PWR-LINE PRO PWR-LINE PRO (PL7510Gi) is a smart...
  • The First MikroTik product with 10G RJ45 Ethernet ports, CRS312-4C+8XG-RM

    CRS312-4C+8XG-RM Switch of the future: the firs...
  • Netflix has identified vulnerabilities in RouterOS.

    Netflix has identified several TCP networking v...

RSS MikroTik Blog

  • CVE-2026-52346
    An out-of-bounds read vulnerability has been identified in MikroTik RouterOS, in the code that inspects TLS traffic for firewall rules that match TLS connections. A specially crafted packet could allow an attacker to crash the router or disclose a limited amount of memory contents. This issue was reported by Rasmus Moorats and is tracked as […]
  • September 2026 vulnerability
    MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels. This is an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information. Your device should already give […]
  • CVE-2025-10948
    A buffer overflow vulnerability has been discovered in MikroTik RouterOS 7, affecting the parse_json_element function within the libjson.so component. The vulnerability is triggered through the /rest/ip/address/print endpoint and can be exploited remotely. The exploit for this issue has been publicly disclosed and may be actively used. Upgrading to RouterOS version 7.20.1 or 7.21beta2 mitigates this […]
  • CVE-2025-6563
    A cross-site scripting (XSS) vulnerability has been discovered in the hotspot functionality of MikroTik RouterOS, affecting versions below 7.19.2. An attacker can inject the javascript protocol via the dst parameter in a crafted URL. When a victim browses to this malicious URL and logs in through the hotspot page, the injected XSS payload executes in […]
  • CVE-2023-47310
    A misconfiguration in the default settings of MikroTik RouterOS 7 allows incoming IPv6 UDP traceroute packets, which could permit unauthorized network reconnaissance from external sources. Users are advised to upgrade to RouterOS 6.49.13, 7.14, or any later version to address this vulnerability. MikroTik always recommends keeping RouterOS devices up to date and using a strong […]
  • CVE-2025-6443
    An improper access control vulnerability has been identified in MikroTik RouterOS, related to the handling of VXLAN source IP addresses. This flaw allows remote attackers to bypass access restrictions on affected installations without requiring authentication. The specific issue exists within the processing of remote IP addresses during VXLAN traffic handling. The router fails to validate […]
  • CVE-2024-54952
    A memory corruption vulnerability has been discovered in the SMB service of MikroTik RouterOS. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets to the SMB service, triggering a null pointer dereference. This results in a remote denial of service (DoS) condition, rendering the SMB service unavailable. Users are advised to upgrade […]
  • CVE-2024-54772
    Issue Summary A vulnerability has been identified in the WinBox service, where a discrepancy in response size between connection attempts with valid and invalid usernames allows attackers to confirm if user accounts exists via brute forcing the login process. In other words, when attacker tries to log into the device, by examining the response, the […]
  • CVE-2024-27686
    The SMB service in RouterOS 6 could be affected by a specially crafted SMB session setup packet. In the reported scenario, this could interrupt the active SMB session, which may also interrupt an ongoing file transfer that depends on that session. This issue is fixed in RouterOS 6.49.14. RouterOS version 7 is not affected. MikroTik […]
  • CVE-2023-41570
    MikroTik RouterOS versions 7.1 through 7.11 contained an access control issue in the REST API. The issue applied to installations where the REST API was enabled and reachable, and could allow requests to be handled with incorrect access control. This issue is fixed in RouterOS 7.12 and newer releases. MikroTik always recommends keeping RouterOS devices […]

General information

MikroTik Training Schedules
My Certificate Validation
Who is my local MikroTik Consultant
How to become a MikroTik Consultant
How to become a MikroTik Certified Trainer

Useful URLs

MikroTik Distributor
MikroTik WiKi "Documentation"
MikroTik useful Articles and Examples
The Dude "Monitoring, Notification, Syslog"
User Manager "Free Radius Server"

Legal

  • Privacy Policy
  • General Term
  • Training terms
  • Managed Services Terms
  • Partner term
  • GET SOCIAL
MikroTik Value Added Distributor, MikroTik Training Centre, MikroTik Toronto, MikroTik Canada

Copyright © 2015 WirelessNetware. All rights reserved.

TOP