Skip to content
Security & Trust

MikroTik RouterOS flaw lets attackers run code as root with one request

CISA says the bug is in the router's web admin service and works before login. The fix is version 7.23 or later.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
MikroTik RouterOS flaw lets attackers run code as root with one request

AI-generated image for WebPulse. About our images

Key finding

Requests needed to trigger the flaw: 1 (Source: CISA ICS advisory ICSA-26-272-06 (September 29, 2026))

A password protects a router only if the flaw sits behind the password. CISA's new advisory on MikroTik RouterOS describes a flaw that sits in front of it. The lesson for leaders: how a device is managed matters as much as how well it is patched.

What CISA reported

CISA published the advisory on September 29, 2026, as ICSA-26-272-06. The problem is in the browser-based admin tool on affected RouterOS versions. Administrators use it to configure the router.

CISA says the tool has an integer underflow in how it handles the body of an HTTP request. The flaw can be reached before login. An attacker on the network needs no credentials. CISA says one crafted request can run code of the attacker's choice as root. It can also knock the service offline, which is a denial of service.

An anonymous researcher reported the flaw to CISA. MikroTik recommends updating RouterOS to version 7.23 or later. CISA lists the affected sectors as Communications and Information Technology.

1
Requests needed to trigger the flaw
Source: CISA ICS advisory ICSA-26-272-06 (September 29, 2026)

How the flaw works

Think of a car's odometer rolling backwards from 000000 and landing on 999999. An integer underflow is the same kind of error. A program subtracts from a number already at its lowest value. The result wraps around to a huge number instead of going negative.

In a typical underflow of this kind, the number is a length. The program then trusts a wrong size and handles more data than it made room for. Attackers often use that gap to overwrite memory and take control.

That is the general pattern, not a confirmed account of this bug. CISA has not published the exact mechanism. The weakness is catalogued as CWE-191.

The key detail is timing. CISA says the code can be reached before authentication. The router handles the request before it asks who sent it. A strong admin password does not help, because the login step never comes into play.

CWE-191 (Integer Underflow)
Weakness class
Source: CISA ICS advisory ICSA-26-272-06 (September 29, 2026)

Why the management page is the real exposure

Root access on a router means control of the device that carries a network's traffic. So where the admin page can be reached matters. If it is open to the internet, anyone online can send the request. If only a locked-down internal network can reach it, an attacker must get inside first.

CISA's standard guidance for industrial control systems (ICS) points the same way. It applies here because CISA lists this flaw in its ICS advisory series. The guidance advises keeping control systems off the internet. It also advises placing them behind firewalls, away from business networks. For remote access, it suggests VPNs. It adds that VPNs can have flaws too, and are only as secure as the devices connected to them.

Some limits apply. The advisory text reviewed here gives no affected version range and no CVE identifier. It does not say how many devices are exposed. CISA says it has received no reports of public exploitation of this flaw. That describes the position at publication, not a guarantee about what follows.

7.23 or later
Fixed in RouterOS version
Source: MikroTik recommendation, as reported in CISA advisory ICSA-26-272-06 (September 29, 2026)

What leaders should ask this week

Start with inventory. Ask your network team how many MikroTik devices you run. Ask which RouterOS version each one uses. Include branch offices, remote sites and devices installed by service providers. These are often missing from asset lists.

Then ask about reach. Can the web admin service be reached from the internet on any device? If so, ask why. Ask whether access can be limited to a management network or a VPN. Closing that path lowers risk even before an update.

Finally, ask about the update. Devices below 7.23 should be checked against the affected-version list in the advisory and given a plan and a date. CISA asks organizations to run their own impact analysis before deploying defensive measures. Test the update on a spare device first. Report suspected malicious activity to CISA.

The takeaway: a flaw that works before login turns a management convenience into an open door. The best place for an admin page is where attackers cannot send it a request at all.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.

Share this insight