CVE-2023-30799: MikroTik RouterOS
High severity, CVSS 7.2. EPSS: 1.4% chance of exploitation in the next 30 days.
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
Affected products
- MikroTik RouterOS: up to and including 6.48.7; from 6.34, before 6.49.7 (fixed in 6.49.7)
Published 2023-07-19. Last modified 2026-06-17.