Posts tagged with “mikrotik”

MikroTik RouterOS CVE-2026-84411 enables pre-auth root RCE

A critical flaw in MikroTik RouterOS can let an attacker take over a router without logging in, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). CISA is the federal agency responsible for coordinating cyber defense for U.S. government networks and critical infrastructure.

The vulnerability, tracked as CVE-2026-84411, sits in the part of RouterOS that handles HTTP requests sent to the web management interface. It is an integer underflow, and it can be triggered before any authentication takes place.

One request is enough

An integer underflow happens when a calculation produces a number smaller than the variable can hold, so the value wraps around to something unexpected. In this case, the bug affects how RouterOS processes the body of incoming HTTP requests.

Read More