Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-67276

Опубликовано: 05 сент. 2026
Источник: nvd
EPSS Низкий

Описание

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

EPSS

Процентиль: 16%
0.00243
Низкий

Дефекты

CWE-347

Связанные уязвимости

github
13 дней назад

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

CVSS3: 8.1
fstec
17 дней назад

Уязвимость реализации протокола SSH операционной системы RouterOS маршрутизаторов MikroTik, позволяющая нарушителю обойти ограничения безопасности и получить доступ на чтение и изменение данных

EPSS

Процентиль: 16%
0.00243
Низкий

Дефекты

CWE-347