CVE-2026-67277

KEV
Published: Set 05, 2026 Last Modified: Set 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,8
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 8,2
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: high

Description

AI Translation Available

RouterOS accepts a 'related' btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With 'random-data=false', the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.

This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0044
Percentile
0,4th
Updated

EPSS Score Trend (Last 5 Days)

306

Missing Authentication for Critical Function

Draft
Common Consequences
Security Scopes Affected:
Access Control Other
Potential Impacts:
Gain Privileges Or Assume Identity Varies By Context
Applicable Platforms
Technologies: Cloud Computing, ICS/OT
View CWE Details
Operating System

Routeros by Mikrotik

Version Range Affected
From 7.0 (inclusive)
To 7.23.4 (exclusive)
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Routeros by Mikrotik

Version Range Affected
From 7.24 (inclusive)
To 7.24.2 (exclusive)
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Routeros by Mikrotik

Version Range Affected
From 6.0 (inclusive)
To 6.49.21 (exclusive)
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026…
https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-…
https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
https://mikrotik.com/supportsec/september-2026-vulnerability/
https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-t…