External risk intelligence

MikroTik RouterOS btest Kernel Restart and Memory Disclosure Vulnerability

CVE advisoryKnown Exploit

CVE-2026-67277

The vulnerability affects RouterOS, the operating system for MikroTik network devices. These devices are commonly deployed as internet-facing edge routers, gateways, and network infrastructure equipment. The btest service, while often used for diagnostics, is a component of this edge-exposed firmware, making it reachable from the network in many typical deployment scenarios.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in MikroTik's RouterOS that allows an unauthenticated user to exploit a flaw in the connection authentication process. This can lead to the disclosure of kernel memory and potentially a denial of service by restarting the system.

  • Unauthenticated access can expose sensitive data.
  • Affects network edge devices, a critical infrastructure component.
  • Confirm relevance and assess exposure of network devices.

Attack Path

How an attacker could exploit the issue

An attacker can initiate a connection to a vulnerable RouterOS device that is exposed to the internet. The device may incorrectly allow a "related" connection before the primary authentication is finished. This allows the attacker to trigger an IPv4 UDP test, which, under specific conditions, sends uninitialized kernel memory data and can cause the device's kernel to restart.

  • Unauthenticated network access required.
  • Triggered by a malformed UDP test connection.
  • Can lead to kernel restart and denial of service.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to send specially crafted packets to a MikroTik router, exploiting a weakness in how the "btest" service handles connections before full authentication. This could lead to the disclosure of uninitialized kernel memory and potentially cause the router's kernel to restart, resulting in a denial of service.

  • Router kernel memory and service availability.
  • Unauthenticated network access to the btest service.
  • Service disruption or kernel restart.

Operational Fix

Recommended remediation, mitigation, and detection steps

Action for this high-severity vulnerability typically falls to network infrastructure or platform teams responsible for managing MikroTik devices. The first practical step is to identify all instances of the affected RouterOS, determine their internet exposure and business criticality, and then locate the accountable owner for remediation planning.

  • Network infrastructure teams own this issue.
  • Verify internet-facing router exposure.
  • Plan urgent vendor-guided updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is MikroTik RouterOS and the btest service?

RouterOS is the software foundation for MikroTik networking hardware, managing routing and firewall functions. It includes a built-in btest service designed for measuring throughput and network performance between devices.

What is the nature of the CVE-2026-67277 vulnerability?

This flaw is classified as CWE-306, Missing Authentication for Critical Function. The system improperly permits specific btest network functions to proceed before the primary authentication session has successfully completed.

How is the kernel state affected by this issue?

The system processes a related btest connection prematurely. By sending a malformed IPv4 UDP test packet with specific size intervals, an unauthenticated actor can induce an unsigned integer underflow, potentially causing a system-wide kernel restart.

Why is this vulnerability considered relevant for infrastructure?

As noted by Halo Surface Signal, MikroTik devices often function as internet-facing gateways. Because the btest service is part of the edge-exposed firmware, the vulnerability is reachable from the network, increasing the risk to critical infrastructure.

How should organizations address this vulnerability?

Infrastructure teams should immediately identify all MikroTik assets, assess their internet exposure, and apply the provided vendor updates. Versions 6.49.21, 7.23.4, and 7.24.2 contain the necessary fixes to resolve the flaw.

References