IM
IronMonkey Threat Research
‹ Back to ICS Advisories

MikroTik RouterOS

CRITICAL
CVSS 9.8
Date 2026-09-29T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-84411 9.8 critical
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

// Affected Products (1)

Vendor Product Asset Type Purdue Level Firmware
MikroTik Unknown network_device -- --

// Remediations (1)

Patch: MikroTik recommends users update RouterOS to version 7.23 or later. The upgrade can be downloaded fr
MikroTik recommends users update RouterOS to version 7.23 or later. The upgrade can be downloaded from the MikroTik website.

// References