The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.
RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download from when using the autoupgrade feature. Therefore, a remote attacker can trick the router into "upgrading" to an older version of RouterOS and possibly reseting all the system's usernames and passwords.
Base Score: 8.5
Impact Score: 7.8
Exploitability Score: 10
Base Score: 7.5
Impact Score: 3.6
Exploitability Score: 3.9
cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:* versions up to 6.44.5 (inclusive)
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* versions up to 6.45.6 (inclusive)