Full Report
MikroTik security advisory (AV26-992)
Analysis Summary
# Vulnerability: MikroTik RouterOS Improper Access Control
## CVE Details
- **CVE ID:** CVE-2026-84411
- **CVSS Score:** 8.8 (High) - *Estimated based on standard RouterOS criticalities for this type of flaw.*
- **CWE:** CWE-284 (Improper Access Control) / CWE-287 (Improper Authentication)
## Affected Systems
- **Products:** MikroTik RouterOS
- **Versions:** All versions prior to **7.24**
- **Configurations:** Systems running RouterOS v7.x with management interfaces (WinBox, WebFig, or API) exposed to untrusted networks.
## Vulnerability Description
The vulnerability involves a flaw in how RouterOS handles authentication or session management within its administrative interfaces. An attacker could potentially bypass security restrictions to gain unauthorized access to the device management functions. Due to the nature of RouterOS, this typically allows for full administrative control over the routing engine and network traffic.
## Exploitation
- **Status:** PoC availability (Note: Information based on current advisory release cycle; check vendor for active exploitation status).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Access to all configuration data and intercepted traffic)
- **Integrity:** High (Ability to modify routing tables, firewall rules, and firmware)
- **Availability:** High (Potential to brick the device or disrupt network services)
## Remediation
### Patches
- **Upgrade to RouterOS v7.24 or later.** MikroTik recommends all users on the v7 branch update immediately to the latest stable release to remediate this flaw.
### Workarounds
- **Filter Management Access:** Restrict access to WinBox (8291), WebFig (80/443), and SSH (22) to specific trusted IP addresses using the `/ip firewall filter` or `/tool bandwidth-server` settings.
- **Disable Unused Services:** Disable management services that are not required under `/ip service`.
- **VPN-only Management:** Require a VPN (such as WireGuard or IPsec) for administrative access rather than exposing ports to the public internet.
## Detection
- **Indicators of Compromise:**
- Unrecognized logins in `/log print`.
- Unexpected scripts or scheduled tasks in `/system script` or `/system scheduler`.
- Unauthorized SOCKS proxies or DNS changes.
- **Detection methods and tools:** Monitor for unusual outbound traffic from the router itself or unexpected changes to the configuration file (`/export`).
## References
- **MikroTik Security:** hxxps[://]mikrotik[.]com/download/changelogs
- **CISA ICS Advisory:** hxxps[://]www[.]cisa[.]gov/news-events/ics-advisories/icsa-26-272-06
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/mikrotik-security-advisory-av26-992