RouterOS WebFig 存在一个未认证的文件读取漏洞,位于 路径。新分配的会话中保留了一个过期的、未初始化的 principal 指针,该指针用于文件授权。未认证的 attacker(攻击者)可以通过操纵内存分配器,使得文件服务路径以足够权限解引用该指针;随后,通过构造包含父目录组件的加密 URI,攻击者可以跳出 WebFig 的文件命名空间,从而泄露由 root 用户拥有的文件,包括包含凭据的配置文件。该问题已在以下版本中修复:6.49.21(长期支持版)、7.23.4(长期支持版)和 7.24.2(稳定
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86060 | 9.2 CRITICAL | SSH session privilege manipulation via a crafted username in Mikrotik RouterOS |
| CVE-2026-67276 | 9.2 CRITICAL | SSH user impersonation possible in Mikrotik RouterOS |
| CVE-2026-67277 | 8.8 HIGH | Kernel memory disclosure and denial of service in MikroTik RouterOS btest service |
| CVE-2026-67279 | 6.9 MEDIUM | SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS |
| CVE-2026-67278 | 6.3 MEDIUM | TLS server impersonation possible in Mikrotik RouterOS |
No comments yet