PT-2026-86453 · Mikrotik · Routeros

·

CVE-2026-67278

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MikroTik RouterOS versions prior to 6.49.21 MikroTik RouterOS versions prior to 7.23.4 MikroTik RouterOS versions prior to 7.24.2
Description RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Due to the inclusion of an e=3 root CA in its trust store, an attacker who controls or redirects an outbound TLS connection can utilize the root public certificate to forge a trusted intermediate certificate and issue certificates for arbitrary hostnames, allowing for TLS server impersonation.
Recommendations Update to version 6.49.21 (Long-term). Update to version 7.23.4 (Long-term). Update to version 7.24.2 (Stable).

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67278

Affected Products

Routeros