Critical Integer Underflow (CVE‑2026‑84411) Enables Unauthenticated Remote Code Execution in MikroTik RouterOS < 7.24
What It Is — A newly disclosed integer underflow (CWE‑191) in the web‑management service of MikroTik RouterOS versions prior to 7.24 allows an unauthenticated attacker to send a crafted HTTP request that triggers arbitrary code execution as root or a denial‑of‑service.
Exploitability — The flaw is reachable without authentication; proof‑of‑concept code has been published and the CVSS v3 base score is 9.8 (Critical). No public exploit‑as‑a‑service is known yet, but the risk of rapid weaponisation is high.
Affected Products — MikroTik RouterOS < 7.24 (all hardware platforms that run the OS).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous firmware inventory and automated patch verification as evidence of due‑diligence.
- Highlights gaps in configuration‑change control; without a documented remediation workflow, auditors cannot verify that a critical network component is protected.
- A successful RCE would break the integrity of the communications layer, undermining the control objective of secure device management that many frameworks map to a single VCF control.
Recommended Actions
- Upgrade every MikroTik device to RouterOS 7.23 or later immediately.
- Run an inventory scan to confirm the OS version on all routers and capture the version data as audit evidence.
- Enable network‑based IDS/IPS signatures that detect the crafted HTTP request pattern.
- Document the remediation in your change‑management system and retain the upgrade logs for future assessments.
Source: CISA Advisory – ICSA‑26‑272‑06