DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

CVE-2026-84411 in MikroTik RouterOS: why a pre-authentication integer underflow reaches root

CVE-2026-84411 in MikroTik RouterOS: why a pre-authentication integer underflow reaches root

The vulnerability in one paragraph

MikroTik RouterOS before 7.24 carries an integer underflow (CWE-191) in the web management service. CISA documented it as ICSA-26-272-06 on September 29, 2026 and rated it CVSS 9.8 Critical. The defect is reachable without credentials: CISA states that a single crafted HTTP request can produce arbitrary code execution as root, or a denial of service.

Where the flaw lives

RouterOS exposes a web management interface for administration. That interface parses the body of incoming HTTP requests. The integer underflow occurs during that parsing, and CISA's advisory places it before the login check. Ordering matters here. A validation defect that executes ahead of authentication is reachable by anyone who can open a TCP connection to the service, which is why the advisory treats the flaw as unauthenticated rather than requiring a valid administrator session.
The affected component is a network service, so exposure is a function of network reachability. A RouterOS management interface bound to a trusted management VLAN and firewalled from the internet presents a far smaller attack surface than the same interface answering requests from any source.

What an attacker gains

The advisory describes two outcomes from the same request. The first is arbitrary code execution with root privileges. The second is a denial of service. Root on a routing device is a strong position. RouterOS devices hold routing tables, firewall policy, VPN configuration and often credentials that other systems trust. An operator who loses that position cannot rely on the device's own filtering to contain the incident.
CISA reports no known public exploitation specifically targeting this vulnerability and no confirmed public proof-of-concept as of the advisory.

Fixing it

Move RouterOS to 7.24.2 or 7.23.4. Those are the fixed releases named in the reporting, and they also close the separate MikroTrick flaws that CERT Polska says have been exploited since early September 2026. Until an upgrade is possible, remove the web management interface from untrusted networks and restrict administrative access to trusted address ranges or a VPN.

Exposure context

A ZoomEye query for the RouterOS application fingerprint returned 2,861,901 matching instances. That figure describes assets matching the product fingerprint, not assets confirmed to run a vulnerable build.

Top comments (0)