Out-of-Bounds Read Vulnerability in MikroTik RouterOS
CVE-2026-7668
Key Information:
Badges
What is CVE-2026-7668?
An out-of-bounds read vulnerability has been identified in MikroTik RouterOS version 6.49.8, specifically within the ASN1_STRING_data function found in the library nova/lib/www/scep.p, which is part of the SCEP Endpoint component. This flaw arises from improper handling of the transactionID and messageType arguments, allowing an attacker to initiate an exploit remotely. The vulnerability is known to be publicly exploitable, and there has been a lack of response from the vendor regarding this security issue following early disclosure attempts.
Affected Version(s)
RouterOS 6.49.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
