CVE-2026-67277
Received Received - Intake

RouterOS IPv4 UDP Test Uninitialized Memory Disclosure

Vulnerability report for CVE-2026-67277, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: CERT.PL

Description

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions:Β 6.49.21 (Long-term),Β 7.23.4 (Long-term)Β andΒ 7.24.2 (Stable)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-06
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
mikrotik routeros 6.49.21
mikrotik routeros 7.23.4
mikrotik routeros 7.24.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

RouterOS has a flaw where it accepts a secondary 'related' btest connection before the primary session completes authentication. An unauthenticated attacker can exploit this to initiate an IPv4 UDP test. When 'random-data=false' is set, the system sends uninitialized kernel packet buffer data. Additionally, an inverted packet-size check causes unsigned integer underflow, leading to abnormally large fragmented packets and potential kernel restart.

Detection Guidance

This vulnerability involves unauthenticated UDP test connections and kernel packet buffer issues in RouterOS. Detection requires checking RouterOS versions for affected releases (below 6.49.21, 7.23.4, or 7.24.2) and monitoring for anomalous large fragmented IPv4 UDP packets. Use RouterOS commands like /system package print to check versions and /interface wireless registration-table print to inspect active connections.

Impact Analysis

This vulnerability allows unauthenticated remote attackers to cause denial-of-service conditions by crashing the RouterOS kernel or triggering abnormal network traffic. It may also expose sensitive data due to uninitialized memory transmission. Systems running vulnerable versions are at risk of instability and potential unauthorized access.

Compliance Impact

The vulnerability allows unauthenticated remote code execution or denial of service via IPv4 UDP tests, which could lead to unauthorized access to sensitive data. This may violate GDPR's data protection requirements (Article 32) and HIPAA's security rules (45 CFR Part 164) by exposing protected health or personal information.

Mitigation Strategies

Upgrade RouterOS to a fixed version: 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable). If upgrading is not immediately possible, disable the btest service or restrict access to trusted networks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67277. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart