Buffer Overflow Vulnerability in MikroTik RouterOS
CVE-2026-67277
Key Information:
Badges
What is CVE-2026-67277?
CVE-2026-67277 is a critical buffer overflow vulnerability found in MikroTik RouterOS, which is a widely used operating system for routing devices. MikroTik RouterOS allows users to manage networking tasks and provides various functionalities essential for maintaining network performance and security. This vulnerability arises when the RouterOS processes "related" btest connections before first completing the required authentication for the primary session. An unauthenticated client can exploit this state to initiate an IPv4 UDP test, which may transmit uninitialized data from a kernel packet buffer, leading to instability within the RouterOS environment. Specifically, this results in an unsigned integer underflow during packet processing, which can generate unusually large fragmented outputs and potentially allow the attacker to restart the RouterOS kernel. Such instability poses a significant risk to organizations utilizing MikroTik devices, affecting their network reliability and security posture.
Potential impact of CVE-2026-67277
-
System Downtime: The exploitation of this vulnerability could enable attackers to cause the RouterOS kernel to restart, resulting in unpredictable behavior and potential downtime for critical network services. This can disrupt business operations and lead to loss of productivity.
-
Unauthorized Access and Control: Given that the vulnerability allows unauthenticated clients to initiate processes, it could facilitate unauthorized access to the network infrastructure. Attackers could leverage this access to manipulate network settings, leading to further exploitation or the establishment of persistent access points within the network.
-
Increased Attack Surface for Subsequent Exploits: By causing instability and allowing unauthorized interactions, this vulnerability could increase the attack surface for further malicious activities. For example, it could be used as a stepping stone for launching more sophisticated attacks, including data exfiltration or lateral movement within the network, thus heightening overall security risks for affected organizations.
CISA has reported CVE-2026-67277
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-67277 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
RouterOS 7.24 < 7.24.2
RouterOS 7.0.0 < 7.23.4
RouterOS 6.0.0 < 6.49.21
References
CVSS V4
Timeline
- 🦅
CISA Reported
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
