---
id: CVE-2026-67277
title: >-
  RouterOS accepts a "related" btest connection before the corresponding primary
  session has completed authentication
summary: >-
  RouterOS accepts a "related" btest connection before the corresponding primary
  session has completed authentication. An unauthenticated client can use this
  state to start an IPv4 UDP test. With "random-data=false", the sender
  transmits a…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'
cwe:
  - CWE-306
vendor: mikrotik
product: routeros
affected:
  - 'routeros >= 6.0, < 6.49.21'
  - 'routeros >= 7.0, < 7.23.4'
  - 'routeros >= 7.24, < 7.24.2'
patched:
  - routeros 7.24.2
published: '2026-09-05'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T12:52:29.533'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67277'
references:
  - url: 'https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve'
    label: cvd@cert.pl
  - url: >-
      https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
    label: cvd@cert.pl
  - url: 'https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802'
    label: cvd@cert.pl
  - url: 'https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801'
    label: cvd@cert.pl
  - url: 'https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800'
    label: cvd@cert.pl
  - url: 'https://mikrotik.com/supportsec/september-2026-vulnerability/'
    label: cvd@cert.pl
  - url: >-
      https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/
    label: cvd@cert.pl
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67277
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-10T19:48:06.780837Z'
scores:
  nvd: 8.2
  cna: 8.8
epss: 0.0156
epssPercentile: 0.74144
kev: true
kevDateAdded: '2026-09-10'
kevDueDate: '2026-09-13'
kevRansomware: false
ingestedAt: '2026-09-06T10:53:52.381Z'
---

## Overview

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.



This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

## Affected

- `routeros >= 6.0, < 6.49.21`
- `routeros >= 7.0, < 7.23.4`
- `routeros >= 7.24, < 7.24.2`

## Remediation

Upgrade past the affected range:

- `routeros 7.24.2`
