MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS btest service missing authentication allows kernel memory disclosure. CVSS 8.2 (high), CISA KEV deadline September 13, 2026.
- Vendor
- MikroTik
- Product
- RouterOS
- CVSS
- 8.2
- EPSS (exploit probability)
- 1.6%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
An unauthenticated client can reach the RouterOS btest (bandwidth test) service without authenticating. The missing authentication check allows the attacker to trigger kernel memory disclosure from the service. Under certain packet-size conditions, the same flaw causes unsigned integer underflow and anomalously large fragmented output, which can restart the RouterOS kernel.
CISA added CVE-2026-67277 to its Known Exploited Vulnerabilities catalog on September 10, 2026. Federal agencies must remediate by September 13, 2026. Per the NVD entry, fixes are in RouterOS 6.49.21, 7.23.4 (Long-term), and 7.24.2 (Stable). Update to your channel’s current fixed version.
