Threat Advisory

MikroTik RouterOS Flaw Lets Attackers Take Full Control Without Authentication

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in MikroTik RouterOS, which can be exploited to take full control of devices without authentication if the device supports remote access using the SSH protocol. The affected versions include 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. This combination of vulnerabilities allows an attacker to hijack MikroTik devices.

CVE-2026-67276 (CVSS 9.2): RouterOS did not properly verify public keys used for SSH authentication, allowing an attacker to craft a different key and log in via SSH without possessing the corresponding private key.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in MikroTik RouterOS, which can be exploited to take full control of devices without authentication if the device supports remote access using the SSH protocol. The affected versions include 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. This combination of vulnerabilities allows an attacker to hijack MikroTik devices.

CVE-2026-67276 (CVSS 9.2): RouterOS did not properly verify public keys used for SSH authentication, allowing an attacker to craft a different key and log in via SSH without possessing the corresponding private key.[emaillocker id="1283"]

CVE-2026-86060 (CVSS 9.2): RouterOS did not properly handle usernames beginning with a disallowed character in the SSH login mechanism, enabling an attacker to elevate their privileges.

CVE-2026-67277 (CVSS 8.8): The bandwidth-test service allowed an unauthenticated connection to enter a state that should only be reachable after logging in, leading to kernel memory leakage or a remote DoS attack.

These vulnerabilities collectively present a significant risk to MikroTik devices with SSH access enabled.

RECOMMENDATION:

We recommend you to update MikroTik RouterOS to version 7.25beta3, 7.24.2, 7.23.4, or 6.49.21.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu