logo

MikroTik RouterOS CVE-2023-30799: On the Dangers of Public Admin Interfaces

ID: eadfb815-23d5-51d6-af84-8589a66f1e60

STIX ID: report--eadfb815-23d5-51d6-af84-8589a66f1e60

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2023-08-07

Date Updated: 2026-04-27

Author: Ivonne Francia; Himaja Motheram

...
...

Censys reports that nearly 450,000 MikroTik RouterOS configuration interfaces on the Internet are running versions vulnerable to CVE-2023-30799, a post-authentication privilege escalation affecting RouterOS before 6.49.7 and long-term through 6.48.6. The report highlights widespread exposure amplified by default "admin" with no password settings, the ease of misconfiguration, historical targeting of MikroTik devices for botnets and proxying, and recommends patching, enforcing strong passwords, and removing public access to management interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.