Vulnerabilities · 3h ago

MikroTik RouterOS Pre-Auth Bug Hands Out Root

CVE-2026-84411 affects MikroTik RouterOS versions before 7.24, where an integer underflow in the web management service can let an unauthenticated network attacker run code as root or trigger a denial of service with one crafted request.

The flaw sits in HTTP request-body handling before login checks. In plain terms, a malformed web request can make the router miscount data and process it the wrong way, so the attacker crosses from a normal request into root-level control without credentials.

For operators, the exposure is wherever RouterOS web management is reachable from untrusted networks: the service itself becomes the attack surface, and a single internet-facing admin interface can turn into full-device takeover before passwords or MFA matter.

CVE-2026-93345

NVD KEV

CVSS 7.5 HIGH: mikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI… EPSS 0.5% (41st percentile).

Timeline

Sources

4 sources covering this story

Entities

Part of the PlainSec briefing for 2026-10-02

Editions

Related stories