Two Critical RouterOS Flaws Allow Unauthenticated Admin Access to Edge Devices
MikroTik RouterOS was found to contain two serious vulnerabilities, CVE-2026-67279 and CVE-2026-86060, patched on 3 September 2026, that together allow attackers to gain full administrative control without a password or key. The first flaw mishandles SSH rekeying during authentication, while the second misinterprets a hyphen-prefixed username as a command option, bypassing login checks entirely. Because RouterOS devices typically sit at the network boundary, exploitation can enable traffic interception, firewall modification, VPN key theft, and persistent account creation. Observed attack activity included creation of a privileged SSH account and exfiltration of device diagnostic files to an external address. Fixes are available in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, and administrators are urged to patch promptly, audit accounts, rotate credentials, and restrict public management access.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in