SSH user impersonation possible in Mikrotik RouterOS
Summary
| CVE | CVE-2026-67276 |
|---|---|
| State | PUBLISHED |
| Assigner | CERT-PL |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-05 20:17:17 UTC |
| Updated | 2026-09-05 21:16:49 UTC |
| Description | RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) |
Risk And Classification
Primary CVSS: v4.0 9.2 CRITICAL from [email protected]
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-347 | CWE-347 CWE-347 Improper verification of cryptographic signature
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 9.2 | CRITICAL | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 9.2 | CRITICAL | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert.pl/en/posts/2026/09/mikrotik-routeros-cve | [email protected] | cert.pl | |
| npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they... | [email protected] | npratley.net | |
| forum.mikrotik.com/t/6-49-21-long-term-is-released/272802 | [email protected] | forum.mikrotik.com | |
| cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-activel... | [email protected] | cert.pl | |
| forum.mikrotik.com/t/7-23-4-long-term-is-released/272801 | [email protected] | forum.mikrotik.com | |
| forum.mikrotik.com/t/7-24-2-stable-is-released/272800 | [email protected] | forum.mikrotik.com | |
| mikrotik.com/supportsec/september-2026-vulnerability | [email protected] | mikrotik.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Sławomir Rozbicki (CERT.PL) (en)
There are currently no legacy QID mappings associated with this CVE.