CVE-2026-67277
HIGH
8,8
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
8,2
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: high
Description
AI Translation Available
RouterOS accepts a 'related' btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With 'random-data=false', the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.
This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0044
Percentile
0,4th
Updated
EPSS Score Trend (Last 5 Days)
306
Missing Authentication for Critical Function
DraftCommon Consequences
Security Scopes Affected:
Access Control
Other
Potential Impacts:
Gain Privileges Or Assume Identity
Varies By Context
Applicable Platforms
Technologies:
Cloud Computing, ICS/OT
Operating System
Routeros by Mikrotik
Version Range Affected
From
7.0
(inclusive)
To
7.23.4
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Routeros by Mikrotik
Version Range Affected
From
7.24
(inclusive)
To
7.24.2
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Routeros by Mikrotik
Version Range Affected
From
6.0
(inclusive)
To
6.49.21
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026…
https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-…
https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
https://mikrotik.com/supportsec/september-2026-vulnerability/
https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-t…