CVE-2023-30799

CRITICAL EXPLOITED IN THE WILD

Mikrotik Routeros < 6.48.7 - Improper Privilege Management

Title source: rule

Description

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.

Exploits (2)

nomisec WRITEUP 1 stars
by alzeer711 · poc
https://github.com/alzeer711/MikroTik-RouterOS-6.49.18-Exploit-Kit
vulncheck_xdb WORKING POC
remote-auth
https://github.com/MarginResearch/FOISted

Scores

CVSS v3 9.1
EPSS 0.0029
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

VulnCheck KEV 2024-09-18
InTheWild.io 2024-09-18
CWE
CWE-269
Status published
Products (2)
mikrotik/routeros < 6.48.7
mikrotik/routeros 6.34 - 6.49.7
Published Jul 19, 2023
Tracked Since Feb 18, 2026