Executive Summary: Critical Pre-Auth RCE Hits MikroTik Routing Infrastructure
The Cybersecurity and Infrastructure Security Agency (CISA) has issued industrial control systems advisory ICSA-26-272-06, warning of a critical vulnerability in MikroTik RouterOS that allows unauthenticated remote attackers to gain full administrative root control over affected hardware. Cataloged as CVE-2026-84411, the flaw carries a near-maximum CVSS v3.1 base score of 9.8 (and a CVSS v4.0 score of 9.3), reflecting its trivial exploitability, lack of authentication barriers, and severe blast radius.
MikroTik RouterOS is deployed globally across internet service provider (ISP) core points-of-presence, enterprise software-defined wide area network (SD-WAN) gateways, and operational technology (OT) industrial fieldbuses. Because the vulnerable component is the primary WebFig web management daemon, any device with its HTTP/HTTPS administrative interface exposed to the internet or an untrusted local subnet can be compromised via a single maliciously constructed HTTP request.
Technical Root Cause: Integer Underflow in WebFig Request Body Handling
The vulnerability (CWE-191: Integer Underflow / Wrap Around) is located in the HTTP server daemon binary (/nova/bin/www) responsible for parsing inbound WebFig and REST API requests. When a client issues a POST request, the handler parses the Content-Length header and subtracts the size of internal header metadata buffers before copying the body payload into memory:
// Vulnerability logic in WebFig body parser routine (/nova/bin/www):
uint32_t content_length = parse_content_length_header(http_req);
uint32_t header_metadata_size = get_processed_metadata_bytes(http_req);
// Integer Underflow flaw:
// If content_length < header_metadata_size, unsigned subtraction wraps around:
uint32_t payload_bytes_remaining = content_length - header_metadata_size; // Wraps to ~4GB (0xFFFFFFxx)
// Allocation vs. Copy mismatch:
char *body_buffer = malloc(content_length + 64);
if (body_buffer) {
// recv() or memcpy() uses the wrapped payload_bytes_remaining value:
read_socket_bytes(sock, body_buffer, payload_bytes_remaining); // Massive Heap Overflow
}
When an adversary submits a request where the declared Content-Length is deliberately smaller than the processed metadata boundary (or zero), the unsigned 32-bit subtraction underflows, wrapping around to a value near (2^{32} - 1) (approximately 4 gigabytes). The subsequent read loop attempts to read up to that wrapped length into a much smaller heap-allocated buffer, causing an unbounded heap overflow that corrupts surrounding chunk descriptors and internal function pointers.
Because the WebFig service runs with elevated root privileges in standard RouterOS kernels, hijacking control flow yields immediate root execution, allowing attackers to manipulate kernel routing tables, install persistent rootkits, or configure silent packet mirroring tunnels.
Exploitation Vector & Threat Landscape
Historically, MikroTik routers have been heavily targeted by threat syndicates (including the Meris, Glupteba, and Mozi botnets) to build massive DDoS amplification armies and establish proxy networks for state-sponsored cyber espionage. The discovery of CVE-2026-84411 gives attackers a zero-interaction weapon that requires no credentials, no user interaction, and no prior reconnaissance:
| Vulnerability Metric | Specification | Defensive Impact |
|---|---|---|
| Attack Vector | Network (AV:N) | Remotely exploitable across public WAN or local LAN. |
| Attack Complexity | Low (AC:L) | Standard HTTP socket requests; no race condition or timing constraints. |
| Privileges Required | None (PR:N) | Pre-authentication trigger; reachable without credentials. |
| User Interaction | None (UI:N) | Completely autonomous exploit flow. |
| Confidentiality / Integrity / Availability | High / High / High | Full compromise of router operating system, routing tables, and credentials. |
Defensive Remediation & RouterOS Hardening Playbook
- Update RouterOS Immediately: Download and install RouterOS 7.24 or later from the official MikroTik repository. The update replaces raw arithmetic operations with safe bounded subtraction routines.
- Disable WebFig on Public WAN Interfaces: Router web management interfaces should never be exposed to public IP space. Disable the HTTP/HTTPS management service or restrict it strictly to local management interfaces using RouterOS IP service rules:
# Disable plaintext HTTP service: /ip service set www disabled=yes # Restrict HTTPS (www-ssl) to authorized management subnets only: /ip service set www-ssl address=10.100.0.0/24 disabled=no - Audit Existing Firewall Filter Rules: Implement strict input filter rules that drop all incoming traffic destined for the router's local management ports from WAN interfaces:
/ip firewall filter add chain=input in-interface-list=WAN protocol=tcp dst-port=80,443 action=drop comment="Drop WAN WebFig access" - Inspect System Scripts and Schedulers: Audit running systems for unauthorized modifications, rogue users, or malicious DNS/NTP alterations that may have been planted prior to patching.



