Vulnerabilities in MikroTik RouterOS that allow remote access via SSH without authentication

The RouterOS operating system used in MikroTik routers has revealed 6 vulnerabilities. The combination of two of these allows remote full control over the device with administrator rights if it is accessible via SSH. Instances of exploitation of these vulnerabilities have been recorded. Patches from MikroTik are available since September 3 (RouterOS 7.25 beta 3, 7.24.2, 7.23.4, 6.49.21), and it is likely that attackers were able to ascertain the nature of the vulnerabilities from these patches.

Vulnerabilities CVE-2026-67276 and CVE-2026-86060 have been assigned a critical severity level (9.2 out of 10). The first issue arises from improper checking of RSA public keys used during SSH authentication. Knowing the username and parameters of the user's public key, an attacker could fabricate a fake key and connect via SSH without access to the private key. The second issue is related to the lack of filtering for invalid characters at the beginning of the username when processing SSH login.

Successful exploitation of the vulnerabilities can be tracked by logs in RouterOS: login failure for user -2 from via ssh user added by ssh:-2@

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster