DEV Community

yutianle
yutianle

Posted on

A first-day response plan for CVE-2026-84411 in MikroTik RouterOS

A first-day response plan for CVE-2026-84411 in MikroTik RouterOS

What is known

CVE-2026-84411 affects MikroTik RouterOS before 7.24. CISA published advisory ICSA-26-272-06 on September 29, 2026, assigning a CVSS score of 9.8 Critical and classifying the weakness as CWE-191, integer underflow. The flaw is in the web management service, it executes before the login check, and CISA states that a single crafted HTTP request can lead to root code execution or a denial of service. No known public exploitation specifically targeting this vulnerability has been reported, and no public proof-of-concept has been confirmed.

Hour one: know your population

List RouterOS devices and their firmware versions. Separate those running a build before 7.24 from those already on a fixed release. Mark which devices accept web management traffic from outside trusted networks. Because the flaw needs no credentials, that last column drives the order of work.

Hours two to six: close the door

For every device that exposes the web management service, remove that reachability. Bind the interface to trusted address ranges, require VPN access for remote administration, and confirm from an external host that the service no longer answers. This step does not require a maintenance window in most environments, which matters given the advisory's severity rating.

Day one close: schedule the upgrade

Plan the move to 7.24.2 or 7.23.4 and verify current release notes on the official MikroTik download page. The same releases also close the MikroTrick flaws that CERT Polska reports have been exploited since early September 2026, so one window covers both. Record the devices that needed access exceptions and note the compensating controls for each.

What to revisit

CISA's statement about the absence of known exploitation is a snapshot. Revisit the exposure inventory if exploitation reporting changes, and use the access logs gathered during the first day as a baseline for later comparison.

Exposure context

A ZoomEye query for the RouterOS application fingerprint returned 2,861,901 matching instances, describing product matches rather than confirmed vulnerable builds.

Top comments (0)