External risk intelligence

RouterOS Web Management Integer Underflow Leads to Unauthenticated Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-84411

The vulnerability affects a web management service on network routing equipment. Such interfaces are frequently exposed to the internet to allow for remote administration and management of the device, and the vulnerability is accessible to unauthenticated users.

Denial of Service

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability affects the web management service on network devices, allowing unauthenticated attackers to potentially execute arbitrary code or cause a denial of service remotely. The primary concern is confirming the relevance and exposure of this specific technology within our environment.

  • Unauthenticated remote attackers can gain full control.
  • This impacts critical network infrastructure if present.
  • Confirming exposure is the immediate leadership concern.

Attack Path

How an attacker could exploit the issue

An attacker on the network could send a specially crafted HTTP request to the router's web management service. Because this service is exposed and does not require authentication, the attacker can exploit an integer underflow flaw in how the request body is processed. Successfully triggering this vulnerability could allow the attacker to gain root-level control of the device or disrupt its operations.

  • Accessible without authentication.
  • Triggered by a single crafted HTTP request.
  • Leads to code execution or denial of service.

Live Threat

Current exploitation, exposure, and threat context

A network attacker could exploit an integer underflow vulnerability in the web management service before authentication. This could allow for arbitrary code execution with root privileges or cause a denial of service on the affected system.

  • System data and access.
  • Crafted HTTP request sent remotely.
  • Full system compromise or outage.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in RouterOS affects the web management service, making it a critical concern for network and security teams responsible for device administration and access control. The immediate priority is to identify all instances of the affected technology, determine their network exposure and business criticality, and assign an owner for remediation planning.

  • Network and security teams own this issue.
  • Verify external reachability and impact.
  • Plan immediate mitigation and vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is RouterOS and its web management service?

RouterOS is the operating system used in MikroTik networking equipment, such as routers and switches, to manage network traffic. The web management service is a built-in interface that allows administrators to configure these devices through a web browser, making it a central point for managing network connectivity, firewall rules, and routing policies.

What does integer underflow mean for CVE-2026-84411?

An integer underflow (CWE-191) occurs when a mathematical calculation results in a number smaller than the system can store, causing it to wrap around to a very large value. In this CVE, the flaw exists in how the web service processes the size of HTTP request data. This unexpected value can confuse the software, allowing an attacker to overwrite memory and potentially run their own commands or crash the service.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a single, specially crafted HTTP request to the device's web management interface. No prior authentication or login is required to initiate the attack. If the request is sent to a device that is not running the affected web management service or is protected by network-level access controls, the trigger path is effectively blocked.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal identifies that this vulnerability affects web management services on routing equipment, which are often intentionally exposed to the internet for remote administration. Because the flaw is reachable without authentication, any device with this interface accessible from the internet is at elevated risk of compromise by external actors.

What should I do if I run this technology?

Prioritize identifying all devices running the affected RouterOS version within your network. Assess whether the web management service needs to be accessible from the network or the internet and restrict access accordingly. Coordinate with your team to monitor official vendor updates and prepare to apply patches as soon as they become available to secure your infrastructure.

References