MikroTik RouterOS and Cloud Hosted Router

Plan PatchCVSS 8.8ICS-CERT ICSA-26-209-05Jul 28, 2026
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

MikroTik RouterOS and Cloud Hosted Router are vulnerable to rapid password guessing due to insufficient rate limiting on failed login attempts. Successful exploitation allows attackers to authenticate as an administrator and gain full control of the router. The vulnerability affects all versions of both products. No vendor patch is available. MikroTik recommends using strong passwords, restricting management access to trusted networks, applying firewall rules, deploying additional authentication layers such as VPN, and limiting unsuccessful-attempt timeframes (0.1–0.5 seconds) in /ip service once the feature is available.

What this means
What could happen
An attacker on your local network or with access to your router's API can guess administrative passwords rapidly due to weak rate limiting, potentially gaining full control of the device and all traffic it routes.
Who's at risk
Network administrators and operators responsible for MikroTik RouterOS devices and Cloud Hosted Routers in environments where the management API, SSH, Winbox, or web interface may be reachable from untrusted networks or the Internet. This includes service providers, ISPs, enterprises with remote access requirements, and municipalities managing network infrastructure.
How it could be exploited
An attacker on the same network segment as your MikroTik router (or accessing the API remotely if exposed) can submit login attempts at high speed because the device does not enforce adequate delays between failed attempts. By systematically guessing passwords, the attacker can authenticate and gain administrative access.
Prerequisites
  • Network access to the management services (API, SSH, Winbox, or web interface port)
  • The router must be reachable from the attacker's network segment or exposed to the Internet
Remotely exploitable if management services are Internet-exposedLow complexity attack (password guessing)No authentication required beyond a usernameNo vendor patch currently availableHigh CVSS score (8.8)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
2 pending
ProductAffected VersionsFix Status
RouterOSAll versionsNo fix yet
Cloud Hosted RouterAll versionsNo fix yet
Remediation & Mitigation
0/6
Do now
0/4
HARDENINGRestrict network access to management services (API, SSH, Winbox, web interface) to trusted networks only using firewall rules
HARDENINGDeploy a VPN or additional authentication layer to protect the API and other management interfaces if they must be accessed over untrusted networks
HARDENINGUse only strong, randomly generated administrative passwords (minimum 16 characters, mixed case, numbers, symbols)
HARDENINGConnect to the router initially from a trusted LAN port only before exposing any management services
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

WORKAROUNDConfigure unsuccessful-attempt rate limiting in /ip service for all management services to 0.1–0.5 seconds between failed attempts once the feature becomes available
Long-term hardening
0/1
HARDENINGMonitor for and review administrative login logs regularly to detect suspicious authentication attempts
API: /api/v1/advisories/84dbfda4-c301-4e29-9138-a942488614a3

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

MikroTik RouterOS and Cloud Hosted Router | CVSS 8.8 - OTPulse