An integer underflow in HTTP request body handling has been identified in the RouterOS web management service (the service behind WebFig, listening on the www and www-ssl ports). A single specially crafted HTTP request, sent without logging in, could crash the service or allow an attacker to execute code on the router with full privileges. This issue has been assigned CVE-2026-84411 and is rated critical.
Who is affected: RouterOS versions before 7.24 (including RouterOS v6), on devices where the web interface is reachable by the attacker.
Who is not affected: Devices already running RouterOS 7.24 or later. This issue is fixed in 7.24, so users on older versions should upgrade to the current stable release.
Fix status:
If you cannot upgrade immediately, make sure the web interface is not reachable from untrusted networks: restrict the www and www-ssl services in the “IP → Services” menu to trusted addresses, or disable them if you manage the router using WinBox or SSH. Note that in the default configuration the firewall already blocks the web interface from the internet, so a device with default firewall rules is only reachable from the local network. Better yet, use a VPN such as WireGuard to reach the router and do not open any management ports at all.
MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall so web and other management services are not reachable from untrusted networks.
This article will be updated with more information in due time.
Contact us about vulnerabilities