CVE CVE-2026-7668
Severity HIGH · CVSS 3.1 7.3 · CVSS 4.0 5.5
Weakness CWE-119, CWE-125
Affected versions 6.49.8
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2026-05-02

What is the CVE-2026-7668 vulnerability?

CVE-2026-7668 is a vulnerability affecting the ASN1_STRING_data function in the nova/lib/www/scep.p library of the SCEP Endpoint component in RouterOS 6.49.8. Manipulation of the transactionID/messageType argument leads to an out-of-bounds memory read. The attack can be initiated remotely, and exploitation code is publicly available.

Which RouterOS versions are vulnerable?

The only version declared vulnerable is 6.49.8. The specific fixed version has not yet been announced; the vendor recommends using the latest v6.x or 7.x version of RouterOS, where the issue should be resolved.

Is my router at risk?

A router is exposed if it is running RouterOS 6.49.8 and the SCEP Endpoint component is active and reachable from untrusted networks. Since the attack requires no authentication (PR:N) and can be initiated remotely, the attack surface depends on the reachability of the SCEP service from outside the local network.

Is the CVE-2026-7668 vulnerability actively exploited?

As of the date of this article, CVE-2026-7668 is not listed in the CISA KEV catalog, and ENISA does not report it as being exploited. However, exploitation code is publicly available and could be used.

How to protect the router from CVE-2026-7668?

Update RouterOS to the latest available v6.x or 7.x version, as recommended by the vendor. Alternatively, if an immediate update is not possible, consider disabling the SCEP Endpoint component or blocking access to the service from untrusted networks via network configuration.

Which RouterOS commands are needed to mitigate CVE-2026-7668?

Update RouterOS

The only definitive fix is an update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2026-7668 require authentication to be exploited?

No, CVE-2026-7668 can be exploited without authentication (PR:N) and without user interaction (UI:N), according to the CVSS 3.1 vector.

What is the CVSS score for CVE-2026-7668?

The CVSS 3.1 score is 7.3 (HIGH), while the CVSS 4.0 score is 5.5 (MEDIUM), both assigned by cna@vuldb.com.

Is CVE-2026-7668 present in the CISA KEV catalog?

No, CVE-2026-7668 is not included in the CISA KEV catalog and is not reported as actively exploited according to ENISA.

Which weaknesses (CWE) are associated with CVE-2026-7668?

CVE-2026-7668 is associated with CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-125 (Out-of-bounds Read).

Which RouterOS version fixes CVE-2026-7668?

The specific patch version has not yet been announced; the vendor recommends using the latest v6.x or 7.x version of RouterOS.

Official sources