CVE-2026-16347
Received Received - Intake

Authentication Bypass in MikroTik RouterOS via Weak API Rate Limiting

Vulnerability report for CVE-2026-16347, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: ICS-CERT

Description

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mikrotik routeros *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MikroTik RouterOS has a weakness in its API authentication that allows too many login attempts without proper restrictions. The system lacks rate-limiting, account lockout, or source-based controls, making it vulnerable to brute-force attacks. Attackers can repeatedly try credentials until they gain unauthorized access to administrative services.

Detection Guidance

Monitor for repeated failed login attempts to MikroTik RouterOS API endpoints. Check logs for high-frequency authentication requests from the same or multiple sources. Use network traffic analysis tools to detect unusual patterns targeting port 8728 or 8729.

Impact Analysis

An attacker could exploit this to gain control of your MikroTik RouterOS device, leading to unauthorized access, data breaches, or network compromise. This may allow them to intercept traffic, install malware, or disrupt services.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection requirements under GDPR and HIPAA. Failure to secure administrative access may result in non-compliance, potential fines, and legal consequences.

Mitigation Strategies

Enable rate-limiting or account lockout in RouterOS settings. Restrict API access to trusted IP addresses using firewall rules. Update RouterOS to the latest version if available. Disable API access if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16347. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart