MikroTik RouterOS and Cloud Hosted Router

Summary

MikroTik RouterOS and Cloud Hosted Router are affected by CVE-2026-16347, a vulnerability that allows attackers to rapidly guess passwords and gain unauthorized system access due to improper restriction of excessive authentication attempts. No fix is currently available, and users are advised to use strong VPNs or other protection layers if the API is exposed to public networks.

IFF Assessment

FOE

This vulnerability allows attackers to gain unauthorized access to systems, posing a direct threat to defenders.

Severity

8.8 High

The CVSS score of 8.8 indicates a high severity. The vulnerability allows for network-based exploitation (Attack Vector: Network) with a high impact on Confidentiality, Integrity, and Availability (Scope: Unchanged). The ease of exploitation, through brute-force password guessing without effective rate-limiting, contributes to its high score.

Defender Context

This vulnerability in MikroTik devices highlights the ongoing risk of weak authentication mechanisms being exploited. Defenders should be vigilant about network segmentation, strong password policies, and implementing additional security layers like VPNs for exposed APIs, especially for critical infrastructure. The lack of an immediate fix emphasizes the need for proactive threat hunting and monitoring for unusual authentication patterns.

Read Full Story →