CVE-2024-54772: MikroTik RouterOS
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.
Affected products
- MikroTik RouterOS: from 6.43, before 6.49.18 (fixed in 6.49.18); from 6.43.13, up to and including 6.49.13; from 7.1, before 7.18 (fixed in 7.18)
Published 2025-02-11. Last modified 2026-06-17.