CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

MikroTik RouterOS and Cloud Hosted Router

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3372

As cited

Copy frozen at (site build).

vulnerabilities

MikroTik RouterOS and Cloud Hosted Router

MikroTik RouterOS and Cloud Hosted Router contain a weakness in API authentication that lacks rate-limiting, account lockout, and source-based restrictions, allowing attackers to conduct password guessing attacks with minimal defensive barriers. The vulnerability affects all versions of both products and carries a CVSS score of 8.8. No patch is currently available; MikroTik recommends mitigations including VPN protection, firewall rules, strong passwords, and restricting management service access to trusted networks.

Why it matters: Network administrators operating MikroTik routers worldwide face immediate risk of unauthorized administrative access through brute-force attacks on exposed management interfaces, requiring urgent implementation of compensating controls until patches are released.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

MikroTik RouterOS and Cloud Hosted Router

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

MikroTik RouterOS and Cloud Hosted Router

MikroTik RouterOS and Cloud Hosted Router contain an authentication flaw (CVE-2026-16347) that allows excessive login attempts without rate limiting or lockout, enabling attackers to brute-force credentials. All versions are affected, and no patch is currently available. Mitigations include restricting management access, using strong passwords, and applying firewall rules.

Why it matters: Organizations using MikroTik RouterOS or Cloud Hosted Router face a high-severity risk of credential brute-forcing leading to unauthorized administrative access; apply mitigations immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

MikroTik RouterOS and Cloud Hosted Router

MikroTik RouterOS and Cloud Hosted Router contain an authentication flaw (CVE-2026-16347) that allows excessive login attempts without rate limiting or lockout, enabling attackers to brute-force credentials. All versions are affected, and no patch is currently available. Mitigations include restricting management access, using strong passwords, and applying firewall rules.

Why it matters: Organizations using MikroTik RouterOS or Cloud Hosted Router face a high-severity risk of credential brute-forcing leading to unauthorized administrative access; apply mitigations immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary