MikroTik RouterOS

MonitorCVSS 4.9ICS-CERT ICSA-26-211-01Jul 30, 2026
Transportation
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary

MikroTik RouterOS contains an information disclosure vulnerability in the API permissions model. Low-privilege API users can extract the router's WireGuard private key in plaintext, enabling VPN impersonation and decryption of all associated traffic. The vulnerability exists across all RouterOS versions. The root cause is that permission policy changes do not automatically log out affected users, allowing them to continue using old (higher) permission levels until their session expires.

What this means
What could happen
An attacker with low-privilege API access to your RouterOS device could extract the WireGuard private key and impersonate your VPN connection, allowing them to decrypt all traffic flowing through that VPN tunnel.
Who's at risk
This affects any organization using MikroTik RouterOS as a VPN gateway or edge router, particularly in transportation networks, logistics, and remote site connectivity where VPN confidentiality is critical. Any site relying on WireGuard for secure site-to-site or remote access tunnels is at risk if API access is granted to lower-privilege users or contractors.
How it could be exploited
An attacker with low-privilege API credentials (such as a junior technician or contractor account) accesses the router's API and retrieves the WireGuard private key in plaintext. With this key, the attacker can impersonate your router on the VPN and intercept or decrypt all traffic encrypted by that VPN tunnel.
Prerequisites
  • API access to the RouterOS device (low-privilege credentials or account)
  • WireGuard VPN configured on the router
  • Attacker credentials not yet revoked or permissions not yet updated
remotely exploitablelow complexityaffects VPN confidentialityrequires valid API credentials but permissions may not be properly enforced
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
RouterOSAll versionsNo fix yet
Remediation & Mitigation
0/4
Do now
0/2
HARDENINGWhen downgrading or removing a user's API permissions, force a full logout of that user so the new permission policy takes effect immediately
HARDENINGRestrict API access to only trusted administrative personnel and use strong, unique credentials for each API user account
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HARDENINGReview all current API user accounts and their permission levels; revoke access for any accounts no longer needed
Long-term hardening
0/1
HARDENINGMonitor router API access logs for any unauthorized queries that retrieve VPN configuration or keys
API: /api/v1/advisories/137b78db-f59e-4410-9936-5ec83085ccc7

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

MikroTik RouterOS | CVSS 4.9 - OTPulse