Malformed Signature Vulnerability in MikroTik RouterOS
CVE-2026-67278

6.3MEDIUM

Key Information:

Vendor

Mikrotik

Status
Vendor
CVE Published:
5 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-67278?

MikroTik RouterOS is susceptible to potential security lapses wherein it improperly processes malformed RSA/PKCS#1 v1.5 signatures during X.509 certificate validation. The inclusion of a specific root CA with exponent e=3 in its trust store allows an attacker with control over the TLS connection to exploit this flaw. By leveraging the public certificate of the root CA, an adversary could forge seemingly legitimate certificates for arbitrary domains, leading to TLS server impersonation and posing severe risks to the integrity of encrypted communications. This issue has been addressed in RouterOS versions 6.49.21, 7.23.4, and 7.24.2.

Affected Version(s)

RouterOS 7.24 < 7.24.2

RouterOS 7.0.0 < 7.23.4

RouterOS 6.0.0 < 6.49.21

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sławomir Rozbicki (CERT.PL)
.