CVE 6.9 MEDIUM

MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds_CVE-2026-7668

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Basic Information

ID CVE-2026-7668
Source VulDB
Published May 2, 2026 at 20:00

Affected Product

Vendor MikroTik
Product RouterOS
Version 6.49.8
Affected Versions MikroTik RouterOS 6.49.8

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.