<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>mikrotik — LowEndSpirit</title>
        <link>https://www.lowendspirit.com/</link>
        <pubDate>Mon, 07 Sep 2026 09:58:58 +0000</pubDate>
        <language>en</language>
            <description>mikrotik — LowEndSpirit</description>
    <atom:link href="https://www.lowendspirit.com/discussions/tagged/mikrotik/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>Critical security vulnerabilities found in MikroTik RouterOS</title>
        <link>https://www.lowendspirit.com/discussion/11331/critical-security-vulnerabilities-found-in-mikrotik-routeros</link>
        <pubDate>Mon, 07 Sep 2026 00:59:14 +0000</pubDate>
        <category>Security</category>
        <dc:creator>oloke</dc:creator>
        <guid isPermaLink="false">11331@/discussions</guid>
        <description><![CDATA[<p>On September 5th, CERT Polska <a rel="nofollow" href="https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve/">published multiple CVEs</a> affecting MikroTik's RouterOS. MikroTik has also published an official <a rel="nofollow" href="https://mikrotik.com/supportsec/september-2026-vulnerability/">vulnerability notice</a> a few days prior.</p>

<p>The discovered security issues enable a remote attacker to gain shell access (ssh service), read arbitrary files (webfig service) or cause service disruption via DoS (btest service).<br />
Below the description of discovered CVEs from <a rel="nofollow" href="https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited">cert.pl</a>:</p>

<blockquote><div>
  <p><strong>CVE-2026-67276 - SSH authentication bypass (CVSS: 9.2)</strong><br />
  RouterOS did not properly verify public keys used for SSH authentication - in particular, it did not compare the entire RSA public key assigned to a user. An attacker who knew the username and the public modulus of the user's key could craft a different key and log in via SSH without possessing the corresponding private key. The privileges obtained were equivalent to those of the targeted account.</p>
  
  <p><strong>CVE-2026-86060 - SSH session privilege manipulation via a crafted username (CVSS: 9.2)</strong><br />
  RouterOS did not properly handle usernames beginning with a disallowed character in the SSH login mechanism. By using a crafted username, an attacker could elevate their privileges. The resulting session had full administrative privileges in the RouterOS system.</p>
  
  <p><strong>CVE-2026-67277 - memory disclosure and crash via bandwidth-test (CVSS: 8.8)</strong><br />
  The bandwidth-test service allowed an unauthenticated connection to enter a state that should only be reachable after logging in. Combined with two separate flaws - disclosure of uninitialized data from the packet buffer and an integer underflow in size validation - this enabled kernel memory leakage or a remote DoS attack leading to a system restart.</p>
</div></blockquote>

<p>The vulnerabilities have already been found to be <a rel="nofollow" href="https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/">exploited in the wild</a>, if you run MikroTik RouterOS anywhere, it's necessary to upgrade to patched versions.<br />
Those are currently: <code>7.25beta3</code> (Beta), <code>v7.24.2</code> (Stable), <code>v7.23.4</code> (Long-term), <code>v6.49.21</code> (Long-term v6).</p>
]]>
        </description>
    </item>
   </channel>
</rss>
