CVE-2026-7668: MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds
A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1STRINGdata in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The exploit is publicly available and might be used. You should upgrade the affected component. The vendor recommends to "use the latest v6.x or 7.x MikroTik RouterOS version, the reported issue should be fixed there."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MikroTik RouterOS SCEP Endpoint (nova/lib/www/scep.p / ASN1_STRING_data)to a version that resolves this vulnerability.Fixed in 6.49.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7668?
CVE-2026-7668 is classified as a high-severity vulnerability in MikroTik RouterOS 6.49.8.
How do I fix CVE-2026-7668?
To fix CVE-2026-7668, upgrade MikroTik RouterOS to the latest version that addresses this vulnerability.
What does CVE-2026-7668 affect?
CVE-2026-7668 affects the ASN1_STRING_data function in the SCEP Endpoint of MikroTik RouterOS 6.49.8.
What is the impact of CVE-2026-7668?
The impact of CVE-2026-7668 can lead to potential out-of-bounds access and may cause application crashes or exploitation.
Is CVE-2026-7668 present in earlier versions of MikroTik RouterOS?
CVE-2026-7668 specifically affects MikroTik RouterOS version 6.49.8 and may not be present in earlier versions.