MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik · RouterOS
Date added (CISA)
2026-09-10
Remediation due
2026-09-13
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Associated with
Related to
←msgbox.execampaignCorrelated cluster2026-09-21
Description
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation.