CVE-2023-30799: MikroTik RouterOS

High severity, CVSS 7.2. EPSS: 1.4% chance of exploitation in the next 30 days.

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.

Affected products

  • MikroTik RouterOS: up to and including 6.48.7; from 6.34, before 6.49.7 (fixed in 6.49.7)

Published 2023-07-19. Last modified 2026-06-17.