As cited
Copy frozen at (site build).
vulnerabilities
MikroTik RouterOS and Cloud Hosted Router
MikroTik RouterOS and Cloud Hosted Router contain a weakness in API authentication that lacks rate-limiting, account lockout, and source-based restrictions, allowing attackers to conduct password guessing attacks with minimal defensive barriers. The vulnerability affects all versions of both products and carries a CVSS score of 8.8. No patch is currently available; MikroTik recommends mitigations including VPN protection, firewall rules, strong passwords, and restricting management service access to trusted networks.
Why it matters: Network administrators operating MikroTik routers worldwide face immediate risk of unauthorized administrative access through brute-force attacks on exposed management interfaces, requiring urgent implementation of compensating controls until patches are released.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
MikroTik RouterOS and Cloud Hosted Router
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
MikroTik RouterOS and Cloud Hosted Router
MikroTik RouterOS and Cloud Hosted Router contain an authentication flaw (CVE-2026-16347) that allows excessive login attempts without rate limiting or lockout, enabling attackers to brute-force credentials. All versions are affected, and no patch is currently available. Mitigations include restricting management access, using strong passwords, and applying firewall rules.
Why it matters: Organizations using MikroTik RouterOS or Cloud Hosted Router face a high-severity risk of credential brute-forcing leading to unauthorized administrative access; apply mitigations immediately.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
MikroTik RouterOS and Cloud Hosted Router
MikroTik RouterOS and Cloud Hosted Router contain an authentication flaw (CVE-2026-16347) that allows excessive login attempts without rate limiting or lockout, enabling attackers to brute-force credentials. All versions are affected, and no patch is currently available. Mitigations include restricting management access, using strong passwords, and applying firewall rules.
Why it matters: Organizations using MikroTik RouterOS or Cloud Hosted Router face a high-severity risk of credential brute-forcing leading to unauthorized administrative access; apply mitigations immediately.
- Source published
- First seen by Cybersecurity Tracker