top of page
perceptive_background_267k.jpg

MikroTik RouterOS and Cloud Hosted Router

Published:

28 juli 2026 om 14:00:00

Alert date:

28 juli 2026 om 18:04:03

Source:

cisa.gov

Click to open the original link from this advisory

Network Infrastructure, Critical Infrastructure, Identity & Access

CISA has published an ICS advisory regarding a high-severity vulnerability (CVE-2026-16347) affecting MikroTik RouterOS and Cloud Hosted Router (all versions). The vulnerability stems from improper restriction of excessive authentication attempts in the API authentication handling, lacking effective rate-limiting, account lockout, or source-based restrictions. Attackers on adjacent networks can bypass a fixed per-connection delay by using concurrent sessions, enabling high-volume brute-force password guessing. The CVSS v3.1 score is 8.8 (HIGH), with attack vector adjacent network, no privileges required, and high impact on confidentiality, integrity, and availability. No patch is currently available from MikroTik. Mitigations include using VPNs, restricting API access to trusted networks, applying firewall rules, and using strong randomly generated passwords. The vulnerability was reported by Andre Santos of União Geek. No known public exploitation has been reported at this time, and the vulnerability is not remotely exploitable.

Technical details

Mitigation steps:

Affected products:

MikroTik RouterOS
MikroTik Cloud Hosted Router

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page