Skip to finding
§
High
Firmware — edge
Confirmed
CVE-2026-84411

One pre-authentication HTTP request can execute code as root on MikroTik RouterOS.

Web-management reachability is the only remote prerequisite established in the public record.

Affects

MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.

What it enables

Unauthenticated arbitrary code execution as root

Reach the RouterOS web-management service.→↓Send one crafted HTTP request body before authentication.→↓Trigger the request-body integer underflow.→↓Execute attacker-controlled code as root.
Why this matters

RouterOS takes the second slot over Firefox because its chain is established from one unauthenticated request to root, while Mozilla's advisory does not establish direct web reachability or host-operating-system execution for any listed flaw.

Detail and 2 sources
Required access

Network reachability to the RouterOS web-management service

Affected versions

RouterOS versions earlier than 7.24, according to CISA's affected-product boundary

A crafted request body reaches an integer underflow before authentication and turns it into attacker-controlled execution as root.

CISA's remediation text says 7.23 or later, while its product-status data marks versions earlier than 7.24 affected; the first fixed release is therefore not settled in the public record.

Evidence
CISA's September 29 CSAF record says the flaw is reachable before authentication and a single crafted request can achieve arbitrary code execution as root.CISA's remediation paragraph says 7.23 or later while its product-status data marks versions earlier than 7.24 affected, so the exact first fixed release is withheld.No public exploit or reported exploitation was found in the completed searches.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 30, 2026