CVE-2026-67277

Published Sep 5, 2026

Last updated a day ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-67277 is a vulnerability affecting the bandwidth-test service within MikroTik RouterOS. This flaw allows an unauthenticated client to establish a "related" btest connection before the primary session has completed its authentication process. An attacker can leverage this state to initiate an IPv4 UDP test. When the `random-data` parameter is set to `false`, the sender transmits an uninitialized tail from a kernel packet buffer, which can lead to the leakage of kernel memory. Additionally, an unchecked, inverted packet-size interval can cause an unsigned integer underflow and anomalously large fragmented output, potentially resulting in a remote denial-of-service (DoS) attack that restarts the RouterOS kernel or crashes the device.

Description
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Source
cvd@cert.pl
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

cvd@cert.pl
CWE-306

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

8

  1. 🧨🧨🧨 MIKROTRICK 🧨🧨🧨 Weaponized MikroTik RouterOS exploitation framework. - CVE-2026-67279 - CVE-2026-86060 - CVE-2026-67276 - CVE-2026-67281 - CVE-2026-67277 - CVE-2026-67278 - CVE-2025-61481 - CVE-2025-10948 - CVE-2018-14847 Now available at my beloved ❤️

    @YogSoth0

    8 Sept 2026

    4098 Impressions

    15 Retweets

    61 Likes

    69 Bookmarks

    4 Replies

    1 Quote

  2. 🚨 Upozorňujeme na kritické zranitelnosti v RouterOS v zařízeních MikroTik, CVE-2026-67277, CVE-2026-86060, CVE-2026-67276. Zranitelnosti umožňují vzdálené spuštění kódu s administrátorskými oprávněními prostřednictvím služby SSH, přičemž exploit zcel

    @GOVCERT_CZ

    8 Sept 2026

    4898 Impressions

    16 Retweets

    42 Likes

    28 Bookmarks

    4 Replies

    0 Quotes

  3. MikroTik RouterOS CVE-2026-67277 (CVSS 8.8) allows unauthenticated btest connections. Review: https://t.co/AqllyUa5F2. https://t.co/YGPNdY0mFz for device assessments. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/sVPtZ1NlOz

    @ADKCyber

    6 Sept 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. #threatreport #LowCompleteness Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended | 05-09-2026 Source: https://t.co/65CMvpHWR2 Key details below ↓ 💀Threats: Mikrotrick_vuln, 🔓CVEs: CVE-2026-67277 https://t.co/MYKMMpT

    @rst_cloud

    6 Sept 2026

    151 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. A severe vulnerability was disclosed for Mikrotik RouterOS (CVE-2026-67277) https://t.co/NZWbjkljQ5

    @vuldb

    5 Sept 2026

    156 Impressions

    0 Retweets

    0 Likes

    2 Bookmarks

    0 Replies

    0 Quotes