← Back to Feed CACHED · 2026-09-30 01:30:43 · CACHE_KEY CVE-2026-84411
CVE-2026-84411 · CWE-191 · Disclosed 2026-09-29

MikroTik RouterOS WebFig Pre-Auth Integer Underflow Root RCE

ASSESSED — NOISGATE
Vendor
—
—
—
Reassessed
—
—
—
Verdict: —
Do you agree?
01 · The Real Story

Someone left the master key under the welcome mat, and the mat is visible from space

CVE-2026-84411 is an integer underflow (CWE-191) in the HTTP request body handler of MikroTik RouterOS's web management service (WebFig). The flaw fires *before* any authentication check, meaning an unauthenticated remote attacker can send a single crafted HTTP request to achieve arbitrary code execution as root — or crash the device outright. Affected versions include the entire RouterOS 7.x line prior to 7.24 and the 6.x line prior to 6.49.21. MikroTik has released patches in 7.24.2, 7.23.4, and 6.49.21. CISA published advisory ICSA-26-272-06 on September 29, 2026.

CISA scored this at CVSS 9.8 and that score is dead-on. There is zero friction in the exploit chain once the web management interface is reachable: no credentials, no user interaction, no complex race condition, no chaining required. MikroTik routers are *network edge appliances by definition* — every single installation sits at a network boundary. Historically, Shodan has indexed between 500,000 and 900,000 internet-facing RouterOS instances, many with web management enabled by default. The blast radius of root on a border router is total: traffic interception, DNS hijacking, VPN tunnelling into the internal network, and pivot to every host behind it. This is not an overhyped desktop vuln; this is a one-shot network takeover.

"Pre-auth root RCE on internet-facing MikroTik routers via a single HTTP request. Patch now."
02 · The Attack Path

4 steps from start to impact.

STEP 01

Identify exposed WebFig service

The attacker scans for MikroTik devices with the WebFig HTTP(S) management interface exposed on ports 80, 443, or 8080. Shodan, Censys, and FOFA queries for MikroTik HttpProxy or the RouterOS login page fingerprint return hundreds of thousands of results. No credentials or interaction is needed for discovery.
Conditions required:
  • Target MikroTik device has WebFig enabled and reachable from attacker's network position
Where this breaks in practice:
  • Some enterprises restrict web management to internal/VPN-only — but MikroTik defaults to allowing it on all interfaces
  • ISP and SOHO deployments overwhelmingly leave it exposed
Detection/coverage: Shodan/Censys asset inventories; external attack surface management (EASM) tools flag exposed MikroTik WebFig services
STEP 02

Send crafted HTTP request triggering integer underflow

The attacker sends a single malformed HTTP request with a manipulated Content-Length or body-length field that triggers the integer underflow in the request body parser. The underflow causes a wrap-around that corrupts memory state before any authentication handler runs. Because the vulnerability is pre-auth, no credentials, session tokens, or prior interaction are required.
Conditions required:
  • Network connectivity to WebFig port
  • Knowledge of the integer underflow trigger (specific malformed HTTP request)
Where this breaks in practice:
  • No public PoC exists as of September 30, 2026 — but the vulnerability class (integer underflow in HTTP parsing) is well-understood and the advisory provides enough detail for skilled researchers to reproduce
  • MikroTik's proprietary OS makes reverse engineering slightly harder than open-source targets
Detection/coverage: WAF or IDS rules inspecting for anomalous Content-Length values or malformed HTTP body framing; deep packet inspection on management interfaces
STEP 03

Achieve arbitrary code execution as root

The memory corruption from the integer underflow is leveraged to hijack control flow and execute attacker-supplied shellcode or ROP chain with root privileges. RouterOS runs on a minimal Linux-derived kernel with limited ASLR and no modern exploit mitigations like CFI. Root on RouterOS means full control of the device's routing table, firewall rules, VPN configurations, and DNS settings.
Conditions required:
  • Successful memory corruption from Step 2
Where this breaks in practice:
  • RouterOS is a proprietary embedded OS — exploit development requires device-specific knowledge
  • No public weaponized exploit yet
Detection/coverage: Device-level detection is extremely limited; RouterOS has minimal logging and no EDR equivalent; look for unexpected configuration changes, new user accounts, or altered firewall rules post-compromise
STEP 04

Establish persistence and pivot

With root access, the attacker installs a persistent backdoor (e.g., scheduled script, rogue admin account, modified firmware). They reconfigure the router to tunnel traffic, alter DNS resolution, or create a reverse VPN into the internal network. Every host behind the compromised router is now reachable. Historical campaigns (Mēris, Slingshot, APT28) have demonstrated exactly this pattern on MikroTik devices.
Conditions required:
  • Root access achieved in Step 3
Where this breaks in practice:
  • None — once root is achieved, the device is fully controlled
Detection/coverage: Monitor for new RouterOS user accounts (/user print), unexpected scripts (/system script print), altered DNS settings (/ip dns print), or new VPN/tunnel interfaces; Shadowserver and GreyNoise honeypots may flag scanning from compromised device IPs
03 · Compensating Control

1
CRITICAL 9.8→LOW 2.0
SEVERITY REDUCED
Disable or restrict WebFig to trusted management IPs immediately — Use /ip service set www address=<mgmt-subnet> and /ip service set www-ssl address=<mgmt-subnet> to bind the HTTP(S) management interface to a trusted management VLAN or specific IP range. This eliminates the remote attack vector entirely. If web management is not needed, disable it: /ip service disable www and /ip service disable www-ssl. Deploy within 3 days per the noisgate mitigation SLA for CRITICAL.
2
CRITICAL 9.8→LOW 2.5
SEVERITY REDUCED
Apply firewall filter rules blocking external access to management ports — Add input chain rules dropping traffic to TCP 80, 443, 8080, 8291 (WinBox), and 22 (SSH) from non-trusted sources: /ip firewall filter add chain=input src-address=!<mgmt-subnet> dst-port=80,443,8080,8291,22 protocol=tcp action=drop. This provides defense-in-depth even if service-level ACLs are misconfigured. Deploy within 3 days.
3
CRITICAL 9.8→IGNORE 0.0
SEVERITY REDUCED
Update RouterOS to patched version (7.24.2 / 7.23.4 / 6.49.21) — Apply the vendor patch. For managed fleets, use MikroTik's auto-upgrade or the Dude/WinBox bulk-update feature. For ISP deployments, schedule a maintenance window. This is the definitive fix. Deploy within 3 days per the noisgate mitigation SLA, remediation within 90 days across the full fleet per the noisgate remediation SLA.
4
CRITICAL 9.8→HIGH 7.5
SEVERITY REDUCED
Deploy network-level IDS/IPS rules for anomalous HTTP to MikroTik management ports — Configure Suricata/Snort/Zeek rules to flag malformed HTTP requests (anomalous Content-Length, oversized or negative body lengths) targeting known MikroTik management ports. This provides detection-in-depth but is not a substitute for patching or access restriction. Deploy within 3 days.
5
CRITICAL 9.8→CRITICAL 9.8
Audit for compromise indicators on existing devices — Check all MikroTik devices for signs of existing compromise: unexpected user accounts (/user print), unknown scripts (/system script print), altered DNS (/ip dns print), rogue VPN interfaces, or log entries showing 'user added by' from unknown IPs. The MikroTrick SSH chain is already being exploited in the wild and patches overlap. Deploy immediately.
What doesn't work
  • WAF in front of MikroTik — MikroTik routers are themselves the network edge; there is typically no WAF sitting in front of the router's management interface. Deploying a reverse proxy in front of a router's admin panel is architecturally impractical.
  • MFA on WebFig — The vulnerability is pre-authentication. MFA or strong passwords are irrelevant because the exploit fires before any credential check occurs.
  • RouterOS firewall on the device itself — If the firewall rules allow HTTP management access (which they must for WebFig to function), the vulnerable code path is reached before the firewall can help. The firewall only helps if it blocks management port access entirely from untrusted sources (which is listed as a compensating control above).
  • Firmware integrity monitoring — RouterOS does not support runtime integrity monitoring or file-integrity checking tools. There is no equivalent of AIDE or Tripwire available on the platform.
04 · Intelligence Metadata

The supporting signals.

In-the-Wild ExploitationNot yet observed for CVE-2026-84411 specifically. However, the related MikroTrick SSH chain (CVE-2026-67276 + CVE-2026-86060) has been actively exploited since September 2, 2026 per CERT Polska, demonstrating strong attacker interest in RouterOS targets.
Proof-of-ConceptNo public PoC as of September 30, 2026. No entries found on pocindex.io, ExploitDB, or GitHub repos named after the CVE. The vulnerability class (integer underflow in HTTP parser) is straightforward to reproduce given the advisory detail — expect weaponization within days to weeks.
EPSS ScoreNot yet scored — CVE-2026-84411 was published September 29, 2026 and has not entered the FIRST EPSS model yet. Given the pre-auth/network/RCE profile, expect a high EPSS score (>0.90) once scored.
KEV StatusNot listed in CISA Known Exploited Vulnerabilities catalog as of September 30, 2026. Given CISA published the ICS advisory (ICSA-26-272-06) directly, KEV addition is likely if exploitation is confirmed.
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — 9.8 CRITICAL. Every base metric is at maximum severity. The v4.0 vector scores 9.3. This is the textbook worst-case network attack profile: no privileges, no interaction, full CIA impact.
Affected VersionsRouterOS 7.0 through 7.24.1 (v7 branch) and 6.0 through 6.49.20 (v6 branch). Virtually all RouterOS deployments running any version prior to the September 2026 patches are vulnerable.
Fixed VersionsRouterOS 7.24.2 (stable), 7.23.4 (LTS backport), 6.49.21 (v6 LTS backport), 7.25beta3 (beta). Available at mikrotik.com/download.
Internet ExposureShodan historically indexes 500,000–900,000 internet-facing MikroTik RouterOS instances. Shadowserver identified ~122,500 with SSH exposed as of September 5, 2026. WebFig (HTTP) exposure is estimated at a comparable or higher scale given default-on behavior. Per Enlyft, MikroTik holds ~7% networking hardware market share with 9,000+ tracked enterprise customers.
Disclosure & AdvisoryCISA published advisory ICSA-26-272-06 on September 29, 2026. MikroTik published a support security page for September 2026 vulnerabilities. Reporter listed as anonymous researcher.
Historical ContextMikroTik RouterOS has a pattern of critical pre-auth vulns: CVE-2018-14847 (Winbox credential leak, used by Mēris botnet), CVE-2023-30799 (privilege escalation, 500K+ exposed). APT28/Fancy Bear has used compromised MikroTik routers for DNS hijacking campaigns. Attacker tooling and knowledge of RouterOS internals is mature.

Sources.

  1. CISA ICS Advisory ICSA-26-272-06
  2. SecurityOnline — Critical MikroTik RouterOS Flaw CVE-2026-84411
  3. MikroTik September 2026 Security Advisory
  4. CERT Polska — MikroTik RouterOS Actively Exploited
  5. The Hacker News — Attackers Hijack MikroTik Routers
  6. Insomnisec — MikroTrick Analysis
  7. MikroTik Router Statistics 2026 — Layer-x
  8. MikroTik Market Share — Enlyft
05 · The Call

Final Verdict
= UNCHANGED to CRITICAL (9.8/10)

Why this verdict

  • Pre-auth, single-request RCE as root: The attack chain has zero authentication friction. No credentials, no user interaction, no multi-step chaining. A single malformed HTTP request yields root. This is the lowest-friction attack profile possible.
  • Canonical network edge appliance — verdict floor is CRITICAL: MikroTik RouterOS runs exclusively on routers and network appliances. 100% of installations occupy the high-value 'network edge appliance' role by definition. Root on a border router gives the attacker traffic interception, DNS hijacking, VPN tunnelling, and a direct pivot to every host on the internal network. The blast radius is fleet-scale.
  • Role multiplier: (a) *Low-value role*: Does not exist — no one runs RouterOS on a workstation or sandbox. (b) *Typical role*: Branch office or SOHO router — compromise gives full control of that site's network traffic and a lateral pivot point. (c) *High-value role*: ISP edge router, enterprise perimeter gateway, ICS/OT network gateway — compromise gives mass traffic interception across thousands of downstream customers, or direct access to OT networks. ≥10% of MikroTik installs serve ISP or enterprise edge roles. The chain succeeds identically in all roles (pre-auth, no config dependency beyond WebFig reachability). Blast radius at the high-value role is fleet-to-supply-chain scale.
  • Massive internet-facing attack surface: 500,000–900,000 RouterOS instances historically visible on Shodan. WebFig is enabled by default on all interfaces. The exposed population dwarfs most CVEs.
  • Active attacker interest in MikroTik: The MikroTrick SSH chain (CVE-2026-67276/CVE-2026-86060) is already being actively exploited as of September 2, 2026. Threat actors are actively scanning for and compromising MikroTik devices right now. CVE-2026-84411 provides an even easier path (HTTP vs SSH, pre-auth vs auth-bypass). Weaponization pressure is extreme.
  • Immature exploit mitigations on RouterOS: RouterOS runs on a minimal Linux-derived kernel with limited ASLR, no CFI, no stack canaries on many code paths, and no EDR/endpoint protection. Memory corruption exploitation is significantly easier than on modern desktop or server operating systems.

Why not higher?

There is no severity above CRITICAL. A CVSS 9.8 with pre-auth network RCE on a canonical network edge appliance is the ceiling of the severity scale.

Why not lower?

Downgrading below CRITICAL would require evidence that the exposed population is negligible (<1% of installs with WebFig reachable) or that the exploit chain has significant practical friction. Neither is true. WebFig is on by default, hundreds of thousands of devices are internet-facing, the chain is a single unauthenticated request, and the target platform lacks modern exploit mitigations. The temporary absence of a public PoC does not justify a downgrade — the vulnerability class is well-understood and the advisory detail is sufficient for rapid reproduction.

06 · Verification

Crowdsourced verification payload.

Run this script from an auditor workstation with SSH access to the target MikroTik device. Invoke as: bash check_cve_2026_84411.sh <router-ip> [ssh-user]. Requires SSH client and valid credentials for the target device. The script checks the RouterOS version and reports whether the device is vulnerable.

noisgate-verify.sh
BASHREAD-ONLYSAFE
#!/usr/bin/env bash
# check_cve_2026_84411.sh — MikroTik RouterOS CVE-2026-84411 checker
# Usage: bash check_cve_2026_84411.sh <router-ip> [ssh-user]
# Exit codes: 1=VULNERABLE, 0=PATCHED, 2=UNKNOWN

set -euo pipefail

HOST="${1:?Usage: $0 <router-ip> [ssh-user]}"
USER="${2:-admin}"

echo "[*] Checking MikroTik RouterOS version on $HOST as $USER..."

# Grab version string via SSH
VERSION_RAW=$(ssh -o ConnectTimeout=10 -o StrictHostKeyChecking=accept-new "${USER}@${HOST}" \
  '/system resource print' 2>/dev/null | grep -i 'version:' | head -1) || {
  echo "UNKNOWN — could not connect to $HOST via SSH"
  exit 2
}

VERSION=$(echo "$VERSION_RAW" | sed -E 's/.*version:[[:space:]]*//' | sed -E 's/[[:space:]].*//' | tr -d '\r')

if [ -z "$VERSION" ]; then
  echo "UNKNOWN — could not parse RouterOS version from output"
  exit 2
fi

echo "[*] Detected RouterOS version: $VERSION"

# Parse major.minor.patch
MAJOR=$(echo "$VERSION" | cut -d. -f1)
MINOR=$(echo "$VERSION" | cut -d. -f2)
PATCH=$(echo "$VERSION" | cut -d. -f3)
PATCH=${PATCH:-0}

# Check if WebFig is enabled
WEBFIG=$(ssh -o ConnectTimeout=10 "${USER}@${HOST}" \
  '/ip service print where name=www' 2>/dev/null | grep -c 'disabled.*no') || WEBFIG=0

if [ "$WEBFIG" -gt 0 ]; then
  echo "[!] WebFig (HTTP) is ENABLED on this device"
else
  echo "[*] WebFig (HTTP) appears disabled (reduced exposure)"
fi

# Version comparison logic
# Fixed versions: 7.24.2, 7.23.4, 6.49.21
vulnerable=0

if [ "$MAJOR" -eq 7 ]; then
  if [ "$MINOR" -ge 25 ]; then
    vulnerable=0  # 7.25+ is safe
  elif [ "$MINOR" -eq 24 ] && [ "$PATCH" -ge 2 ]; then
    vulnerable=0  # 7.24.2+ is safe
  elif [ "$MINOR" -eq 23 ] && [ "$PATCH" -ge 4 ]; then
    vulnerable=0  # 7.23.4+ is safe
  else
    vulnerable=1
  fi
elif [ "$MAJOR" -eq 6 ]; then
  if [ "$MINOR" -gt 49 ]; then
    vulnerable=0
  elif [ "$MINOR" -eq 49 ] && [ "$PATCH" -ge 21 ]; then
    vulnerable=0  # 6.49.21+ is safe
  else
    vulnerable=1
  fi
else
  echo "UNKNOWN — unexpected major version $MAJOR"
  exit 2
fi

if [ "$vulnerable" -eq 1 ]; then
  echo "VULNERABLE — RouterOS $VERSION is affected by CVE-2026-84411"
  echo "  Fix: Update to 7.24.2 / 7.23.4 / 6.49.21"
  echo "  Immediate mitigation: Restrict or disable WebFig access"
  exit 1
else
  echo "PATCHED — RouterOS $VERSION is not affected by CVE-2026-84411"
  exit 0
fi
Peer Review

What defenders are saying.

Submit a review attribution: handle + country only
0 flags selected · stored anonymously