CVE-2026-84411 PUBLISHED

MikroTik RouterOS Integer Underflow

Assigner: icscert
Reserved: 01.09.2026 Published: 02.10.2026 Updated: 02.10.2026

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor MikroTik
Product RouterOS
Versions Default: unaffected
  • affected from 0 to 7.24 (excl.)
  • Version 7.24 is unaffected

Solutions

MikroTik recommends users update RouterOS to version 7.24 or later. The upgrade can be downloaded from the MikroTik website. https://mikrotik.com/download

References

Problem Types

  • CWE-191 CWE