highZero-Day

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability (btest service)

First seen Sep 11, 2026 · Updated Sep 11, 2026

mikrotikrouterosnetwork-infrastructurekevunauthenticateddosmemory-disclosureedge-deviceagent-relevant

CVE-2026-67277 is a missing authentication vulnerability in MikroTik RouterOS's btest (bandwidth test) service, allowing unauthenticated attackers to trigger kernel memory disclosure and denial of service. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a short remediation window (added 2026-09-10, due 2026-09-13).

Technical Analysis

The vulnerability resides in RouterOS's btest service, which lacks proper authentication checks for a critical function, enabling unauthenticated network-based attackers to send crafted requests that leak kernel memory contents or crash the device via denial of service. This class of flaw is particularly dangerous on edge/perimeter devices like MikroTik routers, which are widely deployed as gateways, VPN endpoints, and traffic shapers in enterprise and ISP networks. Successful exploitation could expose sensitive kernel data (potentially including session tokens or configuration secrets) or disrupt network availability, and compromised routers are frequently repurposed for botnet activity or as pivot points for further lateral movement. Organizations running AI agent infrastructure behind or through affected MikroTik routers face risk if the devices are used as network gateways, VPN concentrators, or traffic managers for agent-to-tool or agent-to-API communications, since a DoS or memory leak on this hardware could disrupt agent connectivity or expose credentials/API keys transiting the network.

Affected Systems

MikroTik RouterOS devices with the btest (bandwidth test) service enabled and exposed to network access; specific affected version ranges not disclosed in source data, administrators should consult MikroTik's official advisory for exact version details.

Indicators of Compromise

  • No specific file hashes, IPs, or domains provided in source data; monitor for anomalous btest service traffic and unexpected router reboots/crashes as behavioral indicators.

Remediation Steps

  1. 1

    Apply vendor patch

    Update RouterOS to the latest version containing the fix for CVE-2026-67277 as soon as MikroTik releases it.

  2. 2

    Disable or restrict btest service

    Disable the btest (Bandwidth Test) service if not required, or restrict access to trusted management networks/IP ranges via firewall rules.

  3. 3

    Segment management interfaces

    Ensure router management and diagnostic services are not exposed to the public internet; place them behind VPN or dedicated management VLANs.

  4. 4

    Monitor for exploitation

    Review router logs and network traffic for signs of btest service abuse, unexpected crashes, or memory disclosure attempts.

  5. 5

    Audit agent network dependencies

    Identify any AI agent or automation pipelines relying on network paths through affected MikroTik devices and validate continuity/security controls.

CVE / Advisory IDs

CVE-2026-67277

Industries Most Exposed

TelecommunicationsManaged Service ProvidersEnterprise ITCritical InfrastructureTechnology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.