


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the c…
Published:
1 May 2026 at 22:00:00
Alert date:
2 May 2026 at 22:01:04
Source:
nvd.nist.gov
Network Infrastructure
A vulnerability in MikroTik RouterOS 6.49.8 affects the ASN1_STRING_data function in the SCEP Endpoint component. The vulnerability allows remote attackers to trigger an out-of-bounds read by manipulating the transactionID/messageType arguments. A public exploit is available for this vulnerability. The vendor was notified but did not respond to the disclosure.
Technical details
Mitigation steps:
Affected products:
MikroTik RouterOS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7668
https://github.com/ezio315/cve/issues/4
https://vuldb.com/submit/798623
https://vuldb.com/vuln/360804
https://vuldb.com/vuln/360804/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
