← Browse

CVE-2026-67277

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
8.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
EPSS — probability of exploitation (30 days)
0.9%
57.2th percentile
CISA KEV
Listed
Added 2026-09-10 · patch by 2026-09-13
Weakness / dates
CWE-306
Published 2026-09-05 · modified 2026-09-11

Description

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Affected

mikrotik

References

Official: NVD · CVE.org