RouterOS 在对应的主会话完成认证之前,就接受了“关联”的 btest 连接。未认证的客户机可以利用这一状态发起 IPv4 UDP 测试。当设置 时,发送方会传输来自内核数据包缓冲区的未初始化尾部数据。另一个未被检查的、倒置的数据包大小区间会导致无符号整数下溢,产生异常大的分片输出,并可能重启 RouterOS 内核。 该问题已在以下版本中修复:6.49.21(长期支持版)、7.23.4(长期支持版)和 7.24.2(稳定版)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86060 | 9.2 CRITICAL | SSH session privilege manipulation via a crafted username in Mikrotik RouterOS |
| CVE-2026-67276 | 9.2 CRITICAL | SSH user impersonation possible in Mikrotik RouterOS |
| CVE-2026-67281 | 8.7 HIGH | Unauthenticated file read in Mikrotik RouterOS |
| CVE-2026-67279 | 6.9 MEDIUM | SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS |
| CVE-2026-67278 | 6.3 MEDIUM | TLS server impersonation possible in Mikrotik RouterOS |
No comments yet