在 RouterOS 中,当客户端发起重新密钥交换(rekey)后,服务器会进入 SSH 连接协议阶段,即使从未尝试进行用户身份验证。这使得未认证的客户端能够打开会话通道并发送 exec 请求。在受影响的版本中,服务器会执行该命令,从而允许未认证的用户在 RouterOS 管理的文件命名空间中创建、覆盖和重建文件,其中包括包含配置和诊断数据的支持文件。 该问题已在以下版本中修复: 6.49.21(长期支持版,Long-term) 7.23.4(长期支持版,Long-term) 7.24.2(稳定版,Stable)
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86060 | 9.2 CRITICAL | SSH session privilege manipulation via a crafted username in Mikrotik RouterOS |
| CVE-2026-67276 | 9.2 CRITICAL | SSH user impersonation possible in Mikrotik RouterOS |
| CVE-2026-67277 | 8.8 HIGH | Kernel memory disclosure and denial of service in MikroTik RouterOS btest service |
| CVE-2026-67281 | 8.7 HIGH | Unauthenticated file read in Mikrotik RouterOS |
| CVE-2026-67278 | 6.3 MEDIUM | TLS server impersonation possible in Mikrotik RouterOS |
No comments yet