A first-day response plan for CVE-2026-84411 in MikroTik RouterOS
A first-day response plan for CVE-2026-84411 in MikroTik RouterOS
针对 MikroTik RouterOS 中 CVE-2026-84411 的首日响应计划
What is known CVE-2026-84411 affects MikroTik RouterOS before 7.24. CISA published advisory ICSA-26-272-06 on September 29, 2026, assigning a CVSS score of 9.8 Critical and classifying the weakness as CWE-191, integer underflow. The flaw is in the web management service, it executes before the login check, and CISA states that a single crafted HTTP request can lead to root code execution or a denial of service. No known public exploitation specifically targeting this vulnerability has been reported, and no public proof-of-concept has been confirmed.
已知情况 CVE-2026-84411 影响 7.24 版本之前的 MikroTik RouterOS。美国网络安全与基础设施安全局(CISA)于 2026 年 9 月 29 日发布了公告 ICSA-26-272-06,将该漏洞的 CVSS 评分定为 9.8(严重),并将其归类为 CWE-191(整数下溢)。该缺陷存在于 Web 管理服务中,且在登录检查之前执行。CISA 指出,单个精心构造的 HTTP 请求即可导致 root 权限代码执行或拒绝服务。目前尚未有针对该漏洞的公开利用报告,也未确认存在公开的概念验证(PoC)。
Hour one: know your population List RouterOS devices and their firmware versions. Separate those running a build before 7.24 from those already on a fixed release. Mark which devices accept web management traffic from outside trusted networks. Because the flaw needs no credentials, that last column drives the order of work.
第一小时:盘点资产 列出所有 RouterOS 设备及其固件版本。将运行 7.24 版本之前构建的设备与已更新至修复版本的设备区分开来。标记出哪些设备允许来自受信任网络之外的 Web 管理流量。由于该漏洞无需身份验证,最后一项指标将决定工作的优先级。
Hours two to six: close the door For every device that exposes the web management service, remove that reachability. Bind the interface to trusted address ranges, require VPN access for remote administration, and confirm from an external host that the service no longer answers. This step does not require a maintenance window in most environments, which matters given the advisory’s severity rating.
第二至六小时:关闭入口 对于所有暴露了 Web 管理服务的设备,移除其可访问性。将接口绑定到受信任的地址范围,要求通过 VPN 进行远程管理,并从外部主机确认该服务不再响应。在大多数环境中,此步骤无需停机维护窗口,考虑到该漏洞的严重性评级,这一点至关重要。
Day one close: schedule the upgrade Plan the move to 7.24.2 or 7.23.4 and verify current release notes on the official MikroTik download page. The same releases also close the MikroTrick flaws that CERT Polska reports have been exploited since early September 2026, so one window covers both. Record the devices that needed access exceptions and note the compensating controls for each.
首日收尾:安排升级 计划升级至 7.24.2 或 7.23.4 版本,并核实 MikroTik 官方下载页面上的最新发行说明。这些版本同时修复了 CERT Polska 报告的自 2026 年 9 月初以来已被利用的“MikroTrick”漏洞,因此一个维护窗口即可解决两个问题。记录下需要访问例外的设备,并为每台设备标注补偿性控制措施。
What to revisit CISA’s statement about the absence of known exploitation is a snapshot. Revisit the exposure inventory if exploitation reporting changes, and use the access logs gathered during the first day as a baseline for later comparison.
后续复盘 CISA 关于“尚无已知利用”的声明仅代表当前快照。如果后续出现漏洞利用报告,请重新审查暴露清单,并将第一天收集的访问日志作为后续对比的基准。
Exposure context A ZoomEye query for the RouterOS application fingerprint returned 2,861,901 matching instances, describing product matches rather than confirmed vulnerable builds.
暴露背景 通过 ZoomEye 对 RouterOS 应用指纹进行查询,返回了 2,861,901 个匹配实例,这些数据反映的是产品匹配情况,而非确认存在漏洞的具体版本。