CVE-2026-84411: fallo crítico en MikroTik RouterOS
MikroTik RouterOS Integer Underflow
Publicada el · Actualizada el
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.3epss 0.9%
probabilidad de explotación
0.9%top 40% de las CVE
explotación observada
noninguna fuente lo reporta
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
MikroTik · RouterOSCVEs relacionadas — MikroTik RouterOS
En el mismo producto, de las más peligrosas a las menos.
CVE-2019-3943—CVE-2019-3943EPSS 3.7%CVE-2023-30800HIGHMikroTik RouterOS Web Interface Heap CorruptionEPSS 1.7%CVE-2023-30799CRITICALMikroTik RouterOS Administrator Privilege EscalationEPSS 1.4%CVE-2025-10948HIGHMikroTik RouterOS libjson.so print parse_json_element buffer overflowEPSS 0.8%CVE-2025-6563MEDIUMCross-site scripting via dst parameter in RouterOS WiFi hotspotEPSS 0.7%CVE-2026-89028HIGHMikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndXEPSS 0.6%