Skip to finding
important · Research / RCE

RouterOS has a claimed pre-authentication WebFig-to-root path.

Affects

MikroTik RouterOS, the operating system used by MikroTik routers and network appliances.

The CNA material describes one unauthenticated HTTP request body triggering an integer underflow and root code execution on a reachable WebFig service.

Detail and 2 sources

MikroTik's public changelog did not list the reported 7.24 release when checked, so we cannot establish that the announced fix is shipping from that vendor material.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, October 4, 2026