CVE-2026-16347

HIGH CVSS 4.0: 8.7 EPSS 0.27%
Updated Jul 30, 2026
Mikrotik
Parameter Value
CVSS 8.7 (HIGH)
Type CWE-307
Vendor Mikrotik
Public PoC No

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts.

This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)