SSH Authentication Vulnerability in MikroTik RouterOS
CVE-2026-67276

9.2CRITICAL

Key Information:

Vendor

Mikrotik

Status
Vendor
CVE Published:
5 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-67276?

MikroTik RouterOS contains a vulnerability in its SSH authentication mechanism, which fails to fully compare RSA public keys. While it checks the key type and modulus, the exponent is overlooked. An attacker with knowledge of an authorized RSA modulus can exploit this flaw by supplying a crafted key with an exponent of one, successfully forging a valid signature. Consequently, this enables the attacker to establish an SSH command channel as an authorized user without needing access to their private key. The issue has been addressed in RouterOS versions 6.49.21, 7.23.4, and 7.24.2, and users are advised to update their systems promptly to mitigate the risk.

Affected Version(s)

RouterOS 7.24 < 7.24.2

RouterOS 7.0.0 < 7.23.4

RouterOS 6.0.0 < 6.49.21

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sławomir Rozbicki (CERT.PL)
.