CVE-2019-3981: MikroTik RouterOS

Low severity, CVSS 3.7. EPSS: 1.1% chance of exploitation in the next 30 days.

MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.

Affected products

  • MikroTik RouterOS: before 6.43 (fixed in 6.43)
  • MikroTik Winbox: before 3.20 (fixed in 3.20)

Published 2020-01-14. Last modified 2026-06-17.