Executive Summary
Facts Only
* Affected products are MikroTik RouterOS versions less than 7.24.
* The vulnerability is identified as CVE-2026-84411.
* The flaw involves an integer underflow in HTTP request body handling within the web management service.
* The condition is reachable prior to authentication.
* Exploitation allows unauthenticated network attackers to achieve arbitrary code execution as root or cause a denial of service via a crafted request.
* The vulnerability has a CVSS Base Score of 9.8 (CVSS 3.1) and 9.3 (CVSS 4.0).
* The vendor fix is to update RouterOS to version 7.24 or later.
* Relevant CWE is CWE-191 Integer Underflow (Wrap or Wraparound).
Full Take
From the original · CISA ICS Advisories
Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service.Read the full story at cisa.gov
Sentinel — Human
This text exhibits the characteristics of an official security bulletin, relying on structured data and external attributions, suggesting it is likely a factual report rather than synthetic generation.
