CVE-2026-84411, MikroTik RouterOS: one unauthenticated request to the web management service can run code as root; 7.24 fixes the v7 stable channel and the long-term releases are pending (CVSS 3.1 9.8)
MikroTik names the fix for a pre-auth RouterOS web-interface RCE; the v7 and v6 long-term releases are still pending
Defender actions
- Find every RouterOS device whose www or www-ssl service answers from a network you do not trust and upgrade v7 stable devices to 7.24 or later; where the v7 or v6 long-term release is still pending, restrict www and www-ssl under IP > Services to trusted addresses or disable them and manage the router over WinBox, SSH or a VPN.
Analysis
MikroTik's notice of 2026-10-06 describes an integer underflow in HTTP request body handling of the RouterOS web management service, the service behind WebFig on the www and www-ssl ports: a single specially crafted request sent without logging in could crash the service or let an attacker execute code on the router with full privileges, and MikroTik rates the flaw critical as CVE-2026-84411 (MikroTik, 2026-10-06). CISA's advisory ICSA-26-272-06 describes the same flaw as reachable before authentication, scores it CVSS 3.1 9.8 and records no known public exploitation reported to it (CISA, 2026-09-30). RouterOS versions before 7.24, v6 included, are affected on devices where the attacker can reach the web interface; 7.24 fixes the v7 stable channel, while the v7 long-term and v6 long-term releases were still pending when MikroTik wrote (MikroTik, 2026-10-06). BleepingComputer notes that hackers and botnet malware often target MikroTik flaws and recalls a recent CERT Polska warning of an exploit chain against devices with SSH exposed to the internet (BleepingComputer, 2026-09-30).
Cited evidence
A single specially crafted HTTP request, sent without logging in, could crash the service or allow an attacker to execute code on the router with full privileges.
Note that in the default configuration the firewall already blocks the web interface from the internet, so a device with default firewall rules is only reachable from the local network.
v7 long-term - release pending
No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.
Sources4
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.