DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

Detecting Trust Abuse Around CVE-2026-67278 on RouterOS Devices

Detecting Trust Abuse Around CVE-2026-67278 on RouterOS Devices

Vulnerability overview

CVE-2026-67278 is a MikroTik RouterOS 7.x flaw in RSA/PKCS#1 v1.5 signature verification, disclosed by CERT Polska on 5 September 2026. Affected devices accept malformed signatures in TLS/X.509 certificate validation and RSA SSH host-key authentication. The complete fix ships in RouterOS 7.23.6 and 7.24.3.

Mechanism and exploitation conditions

Because the device trust store holds a root CA certificate with public exponent e=3, an attacker who controls or redirects an outbound TLS connection can build a trusted intermediate and issue certificates for arbitrary host names without holding any private key. RSA-based SSH authentication is weakened by the same check. The attacker needs a redirection position, and the target must run an affected build.

Impact

The flaw does not announce itself like a crash or an exploit drop. The visible signal is misdirected trust: outbound connections reaching unexpected endpoints, certificate chains that should not validate, or management automation talking to hosts it was not configured to reach. Left alone, a device can leak configuration or credential material outward.

Affected products and scope

RouterOS 7.x: from 7.0.0 before 7.23.6, and from 7.24 before 7.24.3. Remediated builds are 7.23.6 (long-term) and 7.24.3 (stable). RouterOS 7.23.4 and 7.24.2 carried an incomplete fix.

Exposure context

ZoomEye reported 9,559 assets for os="RouterOS" && service="ssh" on 23 September 2026, while vul.cve="CVE-2026-67278" returned 0. The product figure counts RouterOS SSH fingerprints rather than confirmed vulnerable devices, and the zero CVE figure does not establish absence. Search link: https://www.zoomeye.ai/searchResult?q=b3M9IlJvdXRlck9TIiAmJiBzZXJ2aWNlPSJzc2gi

Remediation and mitigations

  1. Upgrade to 7.23.6 or 7.24.3 and verify the running version.
  2. Baseline the outbound destinations each device contacts, then alert on new or changed endpoints.
  3. Log and review certificate validation failures rather than discarding them.
  4. Bound management access to trusted networks so a redirection failure is not also a credential exposure.
  5. Treat 7.23.4 and 7.24.2 as unpatched in monitoring and inventory.

References

Top comments (0)