RouterOS: btest Conn Auth Gap & IPv4 UDP Test Int Underflow (7.24.2)
CVE-2026-67277 Published on September 5, 2026
Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.
This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Vulnerability Analysis
CVE-2026-67277 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-67277
Want to know whenever a new CVE is published for MikroTik Routeros? stack.watch will email you.
Affected Versions
Mikrotik RouterOS:- Version 7.24 and below 7.24.2 is affected.
- Version 7.0.0 and below 7.23.4 is affected.
- Version 6.0.0 and below 6.49.21 is affected.