RouterOS 在 SSH 登录路径中存在一个参数处理缺陷。当使用以禁止字符开头的用户名时,攻击者可以修改受信任的 RouterOS 策略掩码(policy mask),从而导致权限提升。利用此漏洞需要一个未认证的 SSH 会话以触达 RouterOS 登录辅助程序。该问题已在以下版本中修复:6.49.21(Lont-term)、7.23.4(Lont-term)和 7.24.2(Stable)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67276 | 9.2 CRITICAL | SSH user impersonation possible in Mikrotik RouterOS |
| CVE-2026-67277 | 8.8 HIGH | Kernel memory disclosure and denial of service in MikroTik RouterOS btest service |
| CVE-2026-67281 | 8.7 HIGH | Unauthenticated file read in Mikrotik RouterOS |
| CVE-2026-67279 | 6.9 MEDIUM | SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS |
| CVE-2026-67278 | 6.3 MEDIUM | TLS server impersonation possible in Mikrotik RouterOS |
No comments yet