GPU VulnDB

Database/Firmware, BMC & network fabric

MikroTik RouterOS: pre-auth btest session leaks kernel buffer data and can restart the device

CVSS 8.8CVE-2026-67277Firmware, BMC & network fabricKnown exploitedcurated

Impact

RouterOS accepts a "related" btest connection before the primary session has authenticated, so an unauthenticated client can start an IPv4 UDP test. With random-data=false the sender transmits an uninitialised tail from a kernel packet buffer, disclosing whatever that memory last held. A separate unchecked, inverted packet-size interval underflows an unsigned integer, producing anomalously large fragmented output and able to restart the RouterOS kernel. On a router carrying management or storage traffic for a GPU fleet, the restart is an outage on a path that is rarely redundant, and it can be triggered repeatedly. This is a distinct flaw from the SSH policy-mask escalation in the same release, though the fix versions are shared; CERT.pl reports the RouterOS set as actively exploited.

Who can reach it

Anyone who can send packets to the device's bandwidth-test service - the management network, or the internet if btest is reachable. No authentication needed.

What to do

Upgrade RouterOS to 6.49.21 (Long-term), 7.23.4 (Long-term) or 7.24.2 (Stable); the upgrade reboots the device, so plan for the link to drop. As an immediate mitigation, disable the bandwidth-test server (/tool bandwidth-server set enabled=no) or firewall its port to trusted sources - the advisory does not list any other workaround.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.