API Authentication Flaw in MikroTik RouterOS
CVE-2026-16347
What is CVE-2026-16347?
CVE-2026-16347 is a vulnerability present in MikroTik RouterOS, a widely used operating system for routers and networking devices. The purpose of RouterOS is to provide robust routing features and network management capabilities for both home and enterprise environments. This specific vulnerability relates to an ineffectual handling of API authentication, which undermines the system's ability to defend against unauthorized access attempts. The lack of effective protective measures such as rate limiting and account lockout enables attackers to launch repeated authentication failures without facing immediate restrictions. As a result, they have a more favorable chance of eventually acquiring valid credentials, leading to unauthorized administrative access and the potential to manipulate network configurations or disrupt services.
Potential Impact of CVE-2026-16347
-
Unauthorized Access: The most immediate risk is the potential for attackers to gain unauthorized control over networking devices. Successful exploitation could allow an attacker to modify settings, monitor traffic, or execute malicious commands.
-
Service Disruption: With administrative access obtained through this vulnerability, an attacker could disrupt normal operations of the network, leading to downtime and loss of service for users. This could have significant financial and reputational repercussions for organizations.
-
Increased Attack Surface: By allowing repeated login attempts without meaningful safeguards, this vulnerability increases the attack surface of affected systems. It may lead to further exploitations, as attackers can leverage the compromised devices to infiltrate additional components of the network or facilitate other malicious activities.
Affected Version(s)
Cloud Hosted Router All versions
RouterOS All versions
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
