← IoT Privacy Database

MikroTik RouterOS

MikroTik · Router / Wi-Fi Motion Sensing

AI-drafted · pending review — this rating was produced by the automated research & verification pipeline and has not yet been signed off by a person.

4.0Surveillance
Index
Policy — what its policy permitsC
Evidence — what research provesC

Appeared in CISA KEV (CVE-2018-7445): MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability

Why this rating

Provisional record auto-promoted from crawler discovery (source=cisa-kev, url=https://nvd.nist.gov/vuln/detail/CVE-2018-7445). Not yet independently rated — unstudied; pending maintainer review.

What it is

Manufacturer
MikroTik
Category
Router / Wi-Fi Motion Sensing
Market status
Current

The evidence 1

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Security advisory · NIST NVD · 2026-07-28

    MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.

    Why it matters here: Auto-promoted from review queue (source=nvd).

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database