One pre-authentication HTTP request can execute code as root on MikroTik RouterOS.
Web-management reachability is the only remote prerequisite established in the public record.
MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.
Unauthenticated arbitrary code execution as root
RouterOS takes the second slot over Firefox because its chain is established from one unauthenticated request to root, while Mozilla's advisory does not establish direct web reachability or host-operating-system execution for any listed flaw.
Detail and 2 sources
A crafted request body reaches an integer underflow before authentication and turns it into attacker-controlled execution as root.
CISA's remediation text says 7.23 or later, while its product-status data marks versions earlier than 7.24 affected; the first fixed release is therefore not settled in the public record.
- access:network:lan
- reachable from the local network
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Reaches end-of-life hardware
- No
The advisory is internally inconsistent: it marks all versions below 7.24 affected while recommending 7.23 or later as remediation.