MikroTik Vulnerabilities and Affected Products
Vulnerabilities associated with WinBox.
Products
Clear product- RouterOS14 vulnerabilities
- Cloud Hosted Router1 vulnerability
- RouterOS-TFTP1 vulnerability
- routeros_tftp1 vulnerability
- WinBox1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password. CWE-300Jan 14, 2020 | CVSS3.7v3.1 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |