CVE-2019-3977: MikroTik RouterOS
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download from when using the autoupgrade feature. Therefore, a remote attacker can trick the router into "upgrading" to an older version of RouterOS and possibly reseting all the system's usernames and passwords.
Affected products
- MikroTik RouterOS: up to and including 6.44.5; up to and including 6.45.6
Published 2019-10-29. Last modified 2026-06-17.