MikroTik RouterOS API lacks ratelimiting, enabling bruteforce attacks
CVE-2026-16347 Published on July 28, 2026

Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.

NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Improper Restriction of Excessive Authentication Attempts

The software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.


Products Associated with CVE-2026-16347

Want to know whenever a new CVE is published for MikroTik Routeros? stack.watch will email you.

 

Affected Versions

MikroTik RouterOS: MikroTik Cloud Hosted Router: