MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
| Software | From | Fixed in |
|---|---|---|
| mikrotik / routeros | - | 6.48.7.x |
| mikrotik / routeros | 6.34 | 6.49.7 |