← Back to Feed

MikroTik RouterOS and Cloud Hosted Router

CVE-2026-16347

July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL

This advisory highlights a vulnerability in MikroTik RouterOS and Cloud Hosted Router, where the API lacks effective rate-limiting or account lockout, allowing rapid password guessing. Attackers can bypass a fixed per-connection delay with concurrent sessions, risking unauthorized administrative access. MikroTik recommends mitigations such as using a VPN and configuring attempt time ranges.

Key Takeaways

  • MikroTik RouterOS and Cloud Hosted Router have improper API authentication restrictions.
  • Attackers can bypass per-connection delays via concurrent sessions to guess passwords rapidly.
  • No fix exists; MikroTik recommends using a VPN and configuring unsuccessful-attempt time ranges.
☕ Buy a Coffee