A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2023-30799

CVE-2023-30799: MikroTik RouterOS Privilege Escalation

CVE-2023-30799 is a privilege escalation vulnerability in MikroTik RouterOS that allows authenticated attackers to escalate from admin to super-admin privileges and execute arbitrary code. This article covers technical details, affected versions, impact, and mitigation strategies.

Updated: May 15, 2026

CVE-2023-30799 Overview

CVE-2023-30799 is a privilege escalation vulnerability in MikroTik RouterOS. Affected versions include stable releases before 6.49.7 and long-term releases through 6.48.6. A remote authenticated attacker with admin credentials can elevate to super-admin through the Winbox or HTTP management interfaces. Once elevated, the attacker can execute arbitrary code on the underlying system. The flaw is classified under [CWE-269] Improper Privilege Management. Public proof-of-concept code is published under the FOISted research project, increasing the likelihood of exploitation against exposed devices.

Critical Impact

Authenticated attackers can escalate from admin to super-admin on Winbox or HTTP interfaces and execute arbitrary code on RouterOS devices.

Affected Products

  • MikroTik RouterOS stable versions before 6.49.7
  • MikroTik RouterOS long-term versions through 6.48.6
  • Devices exposing Winbox or HTTP administrative interfaces

Discovery Timeline

  • 2023-07-19 - CVE-2023-30799 published to NVD
  • 2025-11-21 - Last updated in NVD database

Technical Details for CVE-2023-30799

Vulnerability Analysis

The vulnerability allows a user holding the default admin role to obtain super-admin privileges through the Winbox protocol or the HTTP administrative interface. RouterOS exposes administrative functionality via these channels, and the privilege boundary between admin and super-admin is not correctly enforced. Once an attacker reaches super-admin context, RouterOS permits operations that lead to arbitrary code execution on the device. This converts a standard administrative account compromise into full control of the router. Because RouterOS devices commonly act as edge gateways, this control extends to the surrounding network segments.

Root Cause

The root cause is improper privilege management ([CWE-269]) in the authorization logic of the Winbox and HTTP interfaces. RouterOS does not adequately separate the capabilities exposed to admin versus super-admin sessions during certain operations. The defect allows a logged-in admin user to invoke functionality reserved for super-admin and to influence system-level behavior. The flaw is described in detail in the VulnCheck Security Advisory.

Attack Vector

Exploitation requires network access to a RouterOS device with the Winbox service (TCP 8291) or the HTTP/HTTPS administrative interface reachable. The attacker must already hold valid admin credentials. RouterOS ships with a default admin account that historically had no password on older versions, and credential reuse or weak passwords remain common findings. After authenticating, the attacker issues crafted requests that exercise the privilege escalation path and then leverage super-admin to load code. The proof-of-concept released under the FOISted PoC repository demonstrates this chain.

No verified exploitation code is reproduced here. Refer to the FOISted repository and VulnCheck advisory for technical specifics of the exploit chain.

Detection Methods for CVE-2023-30799

Indicators of Compromise

  • Unexpected authenticated sessions to Winbox (TCP 8291) or the HTTP/HTTPS admin interface from unfamiliar source addresses.
  • Creation of new RouterOS user accounts, scheduler entries, or scripts shortly after an admin login.
  • Modifications to the /system scheduler, /system script, or /file trees that were not made by authorized operators.
  • Outbound connections initiated by the router to attacker-controlled infrastructure following an admin login.

Detection Strategies

  • Forward RouterOS logs to a central SIEM and alert on logins to Winbox or WebFig from non-management subnets.
  • Baseline the set of accounts, scripts, and scheduled jobs on each router and alert on deviations.
  • Inspect network telemetry for Winbox traffic crossing trust boundaries where it is not expected.
  • Monitor for repeated failed authentication attempts preceding successful admin logins, indicating credential brute force.

Monitoring Recommendations

  • Enable RouterOS logging with the info topic for system, account, and critical events and ship logs off-device.
  • Track firmware version inventory across all MikroTik devices and flag any device running below 6.49.7 or 6.48.7.
  • Audit the membership of the full group and any custom groups granting policy password, sensitive, or romon.

How to Mitigate CVE-2023-30799

Immediate Actions Required

  • Upgrade RouterOS stable to 6.49.7 or later, and long-term to 6.48.7 or later.
  • Rotate all admin and other privileged RouterOS account passwords immediately after patching.
  • Restrict Winbox (8291), HTTP (80), and HTTPS (443) access to dedicated management networks using the /ip service address list.
  • Remove or disable any unused administrative accounts and enforce strong, unique passwords on remaining accounts.

Patch Information

MikroTik addresses CVE-2023-30799 in RouterOS 6.49.7 (stable) and 6.48.7 (long-term). Apply the update through the standard /system package update workflow or by uploading the signed NPK package and rebooting. Confirm the running version with /system resource print after reboot. Additional context is available in the VulnCheck Security Advisory.

Workarounds

  • Disable the Winbox and WebFig services on internet-facing interfaces using /ip service disable winbox,www,www-ssl where remote management is not required.
  • Bind administrative services to a management VLAN only and enforce ingress filtering on the WAN interface.
  • Replace the default admin username with a non-default account and remove the original admin user.
  • Require SSH key authentication for any remaining remote administration and disable password-based SSH where feasible.
bash
# Restrict administrative services to a management subnet and disable web access
/ip service set winbox address=192.0.2.0/24
/ip service disable www,www-ssl,telnet,ftp,api
/user set admin password="<strong-rotated-password>"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypePrivilege Escalation

  • Vendor/TechMikrotik Routeros

  • SeverityHIGH

  • CVSS Score7.2

  • EPSS Probability0.24%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-269

  • NVD-CWE-noinfo
  • Technical References
  • GitHub PoC Repository

  • VulnCheck Security Advisory
  • Related CVEs
  • CVE-2025-61481: MikroTik RouterOS/SwOS XSS Vulnerability

  • CVE-2025-10948: MikroTik RouterOS Buffer Overflow Flaw

  • CVE-2025-6443: Mikrotik RouterOS Auth Bypass Vulnerability

  • CVE-2024-54772: MikroTik RouterOS Information Disclosure
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English