CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
Other sources
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.
This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.49.21 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.23.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.24.2
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker can be unauthenticated. They need to reach the RouterOS btest service and establish a related btest connection before the associated primary session finishes authentication.
What impact can exploitation have?
An attacker can trigger disclosure of uninitialized kernel packet-buffer data when starting an IPv4 UDP test with random-data=false. They may also cause unsigned integer underflow that produces abnormally large fragmented output and can restart the RouterOS kernel.
Which RouterOS releases contain the fix?
The issue is fixed in RouterOS 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
What configuration condition is associated with the memory disclosure?
The memory disclosure occurs when the attacker starts an IPv4 UDP test with random-data=false. The provided information does not state whether the btest service or this setting is enabled by default.