Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-67277— Kernel memory disclosure and denial of service in MikroTik RouterOS btest service

Quick assessment

Affected
Mikrotik RouterOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

RouterOS 在对应的主会话完成认证之前,就接受了“关联”的 btest 连接。未认证的客户机可以利用这一状态发起 IPv4 UDP 测试。当设置 时,发送方会传输来自内核数据包缓冲区的未初始化尾部数据。另一个未被检查的、倒置的数据包大小区间会导致无符号整数下溢,产生异常大的分片输出,并可能重启 RouterOS 内核。 该问题已在以下版本中修复:6.49.21(长期支持版)、7.23.4(长期支持版)和 7.24.2(稳定版)。

CVSS 8.8 · High EPSS 0.43% · P37

Affected Version Matrix 3

VendorProduct Version RangeStatus
Mikrotik RouterOS 7.24< 7.24.2 affected
7.0.0< 7.23.4 affected
6.0.0< 6.49.21 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-67277

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
Source: CVE Program / CVE List V5
Vulnerability Description
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Mikrotik RouterOS 7.24 ~ 7.24.2 -

II. Public POCs for CVE-2026-67277

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-67277

登录查看更多情报信息。

Security Blog Posts for CVE-2026-67277 (3)

Vendor Pages for CVE-2026-67277 (4)

Same Patch Batch · Mikrotik · 2026-09-05 · 6 CVEs total

CVE-2026-86060 9.2 CRITICAL SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
CVE-2026-67276 9.2 CRITICAL SSH user impersonation possible in Mikrotik RouterOS
CVE-2026-67281 8.7 HIGH Unauthenticated file read in Mikrotik RouterOS
CVE-2026-67279 6.9 MEDIUM SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
CVE-2026-67278 6.3 MEDIUM TLS server impersonation possible in Mikrotik RouterOS

IV. Related Vulnerabilities

V. Comments for CVE-2026-67277

No comments yet


Leave a comment