Post

MikroTik RouterOS Flaw Lets Attackers Run Code as Root

MikroTik RouterOS Flaw Lets Attackers Run Code as Root

MikroTik RouterOS Flaw Alert 🚨

MikroTik’s RouterOS has a near maximum severity bug: CISA urges updating ASAP! A critical RouterOS flaw can let attackers run code as root without a password. The critical flaw, rated 9.8 out of 10 on the CVSS security score, affects the web management service. If an attacker can reach it from the internet or from inside the network, they can craft a single malicious HTTP request and run code as root.

An anonymous researcher reported the bug directly to the US Cybersecurity and Infrastructure Security Agency (CISA). According to the CISA’s advisory, RouterOS versions earlier than 7.24 are affected, and users are advised to update to the latest version, which is 7.24.5.

Key Details:

  • The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication.
  • This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root or to cause a denial of service, using a single crafted request.
  • MikroTik hasn’t released a separate guidance addressing this specific vulnerability, tracked as CVE-2026-84411.

Exposed MikroTik devices outnumber any other vendor on the internet, with more than 367,000 hosts exposing the RouterOS web interface. Attackers can target them directly from the internet. Currently, CISA has no reports of active exploitation attempts targeting the newly disclosed vulnerability.

Recommendations:

  • Minimize the network exposure of any connected systems, ensuring that they’re not accessible from the internet.
  • Sensitive services should be behind a firewall.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs).

For more information, Read full article.

This post is licensed under CC BY 4.0 by the author.