AI description
CVE-2026-67277 is a vulnerability affecting the bandwidth-test service within MikroTik RouterOS. This flaw allows an unauthenticated client to establish a "related" btest connection before the primary session has completed its authentication process. An attacker can leverage this state to initiate an IPv4 UDP test. When the `random-data` parameter is set to `false`, the sender transmits an uninitialized tail from a kernel packet buffer, which can lead to the leakage of kernel memory. Additionally, an unchecked, inverted packet-size interval can cause an unsigned integer underflow and anomalously large fragmented output, potentially resulting in a remote denial-of-service (DoS) attack that restarts the RouterOS kernel or crashes the device.
- Description
- RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
- Source
- cvd@cert.pl
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 8.8
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- cvd@cert.pl
- CWE-306
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
8
🧨🧨🧨 MIKROTRICK 🧨🧨🧨 Weaponized MikroTik RouterOS exploitation framework. - CVE-2026-67279 - CVE-2026-86060 - CVE-2026-67276 - CVE-2026-67281 - CVE-2026-67277 - CVE-2026-67278 - CVE-2025-61481 - CVE-2025-10948 - CVE-2018-14847 Now available at my beloved ❤️
@YogSoth0
8 Sept 2026
4098 Impressions
15 Retweets
61 Likes
69 Bookmarks
4 Replies
1 Quote
🚨 Upozorňujeme na kritické zranitelnosti v RouterOS v zařízeních MikroTik, CVE-2026-67277, CVE-2026-86060, CVE-2026-67276. Zranitelnosti umožňují vzdálené spuštění kódu s administrátorskými oprávněními prostřednictvím služby SSH, přičemž exploit zcel
@GOVCERT_CZ
8 Sept 2026
4898 Impressions
16 Retweets
42 Likes
28 Bookmarks
4 Replies
0 Quotes
MikroTik RouterOS CVE-2026-67277 (CVSS 8.8) allows unauthenticated btest connections. Review: https://t.co/AqllyUa5F2. https://t.co/YGPNdY0mFz for device assessments. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/sVPtZ1NlOz
@ADKCyber
6 Sept 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#threatreport #LowCompleteness Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended | 05-09-2026 Source: https://t.co/65CMvpHWR2 Key details below ↓ 💀Threats: Mikrotrick_vuln, 🔓CVEs: CVE-2026-67277 https://t.co/MYKMMpT
@rst_cloud
6 Sept 2026
151 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A severe vulnerability was disclosed for Mikrotik RouterOS (CVE-2026-67277) https://t.co/NZWbjkljQ5
@vuldb
5 Sept 2026
156 Impressions
0 Retweets
0 Likes
2 Bookmarks
0 Replies
0 Quotes