CISA warns of critical pre-authentication flaw in MikroTik RouterOS
CISA says RouterOS versions earlier than 7.24 contain an integer-underflow vulnerability in HTTP request handling that an unauthenticated network attacker could exploit with a crafted request to execute code as root or cause denial of service. The advisory rates the flaw critical and recommends updating; it notes MikroTik’s guidance to install version 7.23 or later.
Why it matters For operators whose RouterOS management service is reachable by an attacker, authentication is not a barrier to root-level compromise or service disruption.
What to watch next The unresolved question is which minimum release resolves the flaw: the advisory lists versions below 7.24 as affected but recommends 7.23 or later.
US Certs Alerts ↗