Impact
An integer underflow exists in the HTTP request body handling of the RouterOS web management service, allowing an attacker to send a single crafted request that reaches the system before authentication. This flaw can be leveraged by an unauthenticated network adversary to execute arbitrary code with root privileges on the router, or alternatively to trigger a denial of service. The resulting impact compromises confidentiality, integrity, and availability of the device and any networks it connects to.
Affected Systems
The vulnerability affects MikroTik RouterOS installations. All releases older than RouterOS 7.24 are impacted; the vendor recommends updating to version 7.24 or later to obtain the fix.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity risk; exposure to the Web Management interface allows local network attackers to exploit the flaw via a crafted HTTP request without authentication. Although EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, the straightforward exploit path and potential for remote root execution make the threat significant. Administrative controls that deny access to the management interface mitigate the attack surface until the firmware update is applied.
OpenCVE Enrichment