Integer Underflow Vulnerability in RouterOS Web Management Service
CVE-2026-84411
Key Information:
Badges
What is CVE-2026-84411?
CVE-2026-84411 is a significant vulnerability found in the RouterOS web management service developed by Mikrotik. RouterOS is a widely used system for managing network routers, and it provides various functionalities for network configuration and monitoring. This specific vulnerability is categorized as an integer underflow issue within the HTTP request body handling, which poses a serious risk to organizations that rely on this software for network administration. The vulnerability can be exploited by attackers without the need for authentication, potentially allowing unauthorized individuals to execute arbitrary code as a root user or to trigger a denial of service (DoS) condition in the affected systems. The ability to manipulate RouterOS through crafted HTTP requests can lead to severe consequences, including full control of network devices and disruption of services.
Potential impact of CVE-2026-84411
-
Arbitrary Code Execution: The vulnerability allows unauthenticated attackers to remotely execute arbitrary code on affected devices. This could lead to unauthorized control over router functionalities, granting attackers the opportunity to manipulate network traffic, install malware, or exfiltrate sensitive data.
-
Denial of Service (DoS): By triggering the integer underflow vulnerability, attackers can cause a denial of service, which disrupts legitimate users' access to critical network services. This can have serious implications for organizational operations, including downtime and loss of productivity.
-
Network Integrity Compromise: Successfully exploiting this vulnerability could severely undermine the integrity of the network infrastructure. Attackers could use compromised routers as entry points for further attacks within an organization’s network, potentially leading to broader security incidents that undermine both data confidentiality and availability.
Affected Version(s)
RouterOS 0 < 7.24
RouterOS 7.24
News Articles
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.
2 days ago
References
CVSS V4
Timeline
Vulnerability published
- đź“°
First article discovered by BleepingComputer
Vulnerability Reserved
