IM
IronMonkey Threat Research
‹ Back to ICS Advisories

MikroTik RouterOS

MEDIUM
CVSS 4.9
Date 2026-07-30T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-14227 4.9 medium
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.

// Affected Products (1)

Vendor Product Asset Type Purdue Level Firmware
MikroTik Unknown network_device -- --

// Remediations (2)

Mitigation: MikroTik recommends administrators to ensure that when a user's permissions are downgraded, the affe
MikroTik recommends administrators to ensure that when a user's permissions are downgraded, the affected user is fully logged out so the new policy can take effect.
Mitigation: For more information, contact MikroTik (https://mikrotik.com/support).
For more information, contact MikroTik (https://mikrotik.com/support).

// References