CVE CVE-2026-67277
Severity HIGH · CVSS 3.1 8.2 · CVSS 4.0 8.8
Weakness CWE-306
Affected versions < 6.49.21, < 7.23.4, < 7.24.2
First non-vulnerable version 6.49.21, 7.23.4, 7.24.2 (per branch)
Actively exploited YES — CISA KEV catalog since 2026-09-10
CISA Advisory none
Published 2026-09-05

What is the CVE-2026-67277 vulnerability?

RouterOS accepts a “related” btest connection before the primary session has completed authentication. An unauthenticated client can exploit this state to initiate a UDP IPv4 test. With the “random-data=false” setting, the sender transmits an uninitialized tail from a kernel packet buffer. An inverted and unverified packet size range causes an unsigned integer underflow, anomalous fragmented output, and can restart the RouterOS kernel.

Which RouterOS versions are vulnerable?

The vulnerable versions are all those lower than 6.49.21, 7.23.4, and 7.24.2. The fixed versions are:

  • 6.49.21 (Long-term)
  • 7.23.4 (Long-term)
  • 7.24.2 (Stable)

Is my router at risk?

A router is exposed if the Bandwidth Test (btest) service is active and reachable from untrusted networks. The flaw specifically concerns the btest server, which should only be enabled during bandwidth tests. If the service is disabled or unreachable from the Internet, the risk is mitigated.

Is the CVE-2026-67277 vulnerability actively exploited?

Yes, the vulnerability is in the CISA KEV catalog and is reported as actively exploited. It was added to the catalog on September 10, 2026. ENISA reports it as exploited since September 5, 2026 (EUVD-2026-72025).

How to protect the router from CVE-2026-67277?

Immediately update RouterOS to versions 6.49.21, 7.23.4, or 7.24.2, depending on the release line in use. If an immediate update is not possible, disable the Bandwidth Test (btest) service to eliminate the attack surface. Verify that the service is not reachable from external networks.

Which RouterOS commands are needed to mitigate CVE-2026-67277?

Temporary mitigation: btest service

The flaw concerns the Bandwidth Test server, which should only be enabled during tests.

/tool bandwidth-server set enabled=no

Updating RouterOS

The only definitive fix is the update. Save the configuration first; the installation restarts the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score of CVE-2026-67277?

CVE-2026-67277 has a CVSS v3.1 score of 8.2 (High) and a CVSS v4.0 score of 8.8 (High).

Is authentication required to exploit CVE-2026-67277?

No, CVE-2026-67277 can be exploited by an unauthenticated client because RouterOS accepts “related” btest connections before the primary session authentication is completed.

What is the minimum RouterOS version that fixes CVE-2026-67277?

The minimum versions that fix CVE-2026-67277 are 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).

Is disabling the btest service enough to mitigate CVE-2026-67277?

Yes, disabling the Bandwidth Test (btest) service removes the attack surface for CVE-2026-67277, as the vulnerability is specific to the btest server.

Is CVE-2026-67277 in the CISA KEV catalog?

Yes, CVE-2026-67277 is in the CISA KEV catalog and was added on September 10, 2026.

Official sources