CVE-2019-13074: MikroTik RouterOS

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.

Affected products

  • MikroTik RouterOS: up to and including 6.44.3

Published 2019-07-03. Last modified 2026-06-17.