CVE-2026-84411: MikroTik RouterOS Integer Underflow
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MikroTik RouterOSto a version that resolves this vulnerability.Fixed in 7.24
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Any affected MikroTik RouterOS device with its web management service reachable by a network attacker is exposed. Exploitation does not require authentication or user interaction.
What does an attacker need to do to exploit this issue?
An attacker needs network access to the RouterOS web management service and can trigger the flaw with a single crafted HTTP request body. The reported impact includes root-level arbitrary code execution or denial of service.
Is this limited to authenticated administrators or nondefault configurations?
No. The vulnerable HTTP request handling is reachable before authentication, so administrative credentials are not required. The available information does not state whether the web management service is enabled by default.
What can be done if updates cannot be applied immediately?
Restrict network access to the RouterOS web management service so untrusted network attackers cannot reach it. The provided information does not identify a configuration-level fix or other mitigation.