CVE-2026-67277
Received
Received - Intake
RouterOS IPv4 UDP Test Uninitialized Memory Disclosure
Vulnerability report for CVE-2026-67277, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-05
Last updated on: 2026-09-05
Assigner: CERT.PL
Description
Description
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.
This issue was fixed in versions:Β 6.49.21 (Long-term),Β 7.23.4 (Long-term)Β andΒ 7.24.2 (Stable)
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mikrotik | routeros | 6.49.21 |
| mikrotik | routeros | 7.23.4 |
| mikrotik | routeros | 7.24.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |