CVE-2026-93345
CVSS 7.5 HIGH: mikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI… EPSS 0.5% (41st percentile).
Vulnerabilities · 3h ago
CVE-2026-84411 affects MikroTik RouterOS versions before 7.24, where an integer underflow in the web management service can let an unauthenticated network attacker run code as root or trigger a denial of service with one crafted request.
The flaw sits in HTTP request-body handling before login checks. In plain terms, a malformed web request can make the router miscount data and process it the wrong way, so the attacker crosses from a normal request into root-level control without credentials.
For operators, the exposure is wherever RouterOS web management is reachable from untrusted networks: the service itself becomes the attack surface, and a single internet-facing admin interface can turn into full-device takeover before passwords or MFA matter.
CVSS 7.5 HIGH: mikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI… EPSS 0.5% (41st percentile).
4 sources covering this story
MikroTik RouterOS Integer Underflow
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication.
Risolta vulnerabilità in MikroTik RouterOS
Aggiornamenti di sicurezza per MikroTik RouterOS sanano una vulnerabilità con gravità "critica".
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.
MikroTik RouterOS Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service.
Part of the PlainSec briefing for 2026-10-02