Full Report
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]
Analysis Summary
# Vulnerability: Pre-authentication RCE in MikroTik RouterOS Web Management
## CVE Details
- **CVE ID:** CVE-2026-84411
- **CVSS Score:** 9.8 (Critical) - *Estimated based on pre-auth RCE impact*
- **CWE:** CWE-191 (Integer Underflow)
## Affected Systems
- **Products:** MikroTik RouterOS
- **Versions:**
- All versions below 7.24 (Current CISA guidance)
- Note: Conflicting reports suggest updating to at least 7.23 or later.
- **Configurations:** Systems with the web-management interface (WinBox/WebFig HTTP service) exposed to the network.
## Vulnerability Description
The flaw exists within the web management service's handling of HTTP request bodies. An integer underflow occurs during the processing of these requests before the user is authenticated. By sending a single, specifically crafted HTTP request, a remote unauthenticated attacker can trigger the underflow, leading to a buffer overflow or logic error that grants arbitrary code execution with root-level privileges or causes the device to crash (Denial of Service).
## Exploitation
- **Status:** Not currently known to be exploited in the wild (per CISA); No public PoC available as of publication.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full access to device data and traffic)
- **Integrity:** High (Root-level execution allows full device compromise)
- **Availability:** High (Can trigger a Denial of Service condition)
## Remediation
### Patches
MikroTik has released updated versions that address this flaw. Users should upgrade to the following or newer:
- **Stable Channel:** RouterOS v7.24.4
- **Long-term Channel:** RouterOS v7.23.7
### Workarounds
- **Disable Web Management:** If not required, disable the `www` (HTTP) and `www-ssl` (HTTPS) services in `/ip service`.
- **Restrict Access:** Use Firewall Filter rules to restrict access to the web management ports (80/443) to trusted source IP addresses only.
- **Service Relocation:** Move web management to a non-standard port to reduce exposure to automated scanners.
## Detection
- **Indicators of Compromise:**
- Unexpected reboots or service crashes of the web interface.
- Unauthorized configuration changes or new user accounts.
- Unusual outbound traffic originating from the router itself.
- **Detection methods:** Monitor system logs for repeated crashes of the web management process. Audit `/ip service` to ensure only necessary management interfaces are active.
## References
- CISA Advisory (ICSA-26-272-06): hxxps[://]www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
- MikroTik Downloads: hxxps[://]mikrotik.com/download
- BleepingComputer Report: hxxps[://]www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/