Detecting Trust Abuse Around CVE-2026-67278 on RouterOS Devices
Vulnerability overview
CVE-2026-67278 is a MikroTik RouterOS 7.x flaw in RSA/PKCS#1 v1.5 signature verification, disclosed by CERT Polska on 5 September 2026. Affected devices accept malformed signatures in TLS/X.509 certificate validation and RSA SSH host-key authentication. The complete fix ships in RouterOS 7.23.6 and 7.24.3.
Mechanism and exploitation conditions
Because the device trust store holds a root CA certificate with public exponent e=3, an attacker who controls or redirects an outbound TLS connection can build a trusted intermediate and issue certificates for arbitrary host names without holding any private key. RSA-based SSH authentication is weakened by the same check. The attacker needs a redirection position, and the target must run an affected build.
Impact
The flaw does not announce itself like a crash or an exploit drop. The visible signal is misdirected trust: outbound connections reaching unexpected endpoints, certificate chains that should not validate, or management automation talking to hosts it was not configured to reach. Left alone, a device can leak configuration or credential material outward.
Affected products and scope
RouterOS 7.x: from 7.0.0 before 7.23.6, and from 7.24 before 7.24.3. Remediated builds are 7.23.6 (long-term) and 7.24.3 (stable). RouterOS 7.23.4 and 7.24.2 carried an incomplete fix.
Exposure context
ZoomEye reported 9,559 assets for os="RouterOS" && service="ssh" on 23 September 2026, while vul.cve="CVE-2026-67278" returned 0. The product figure counts RouterOS SSH fingerprints rather than confirmed vulnerable devices, and the zero CVE figure does not establish absence. Search link: https://www.zoomeye.ai/searchResult?q=b3M9IlJvdXRlck9TIiAmJiBzZXJ2aWNlPSJzc2gi
Remediation and mitigations
- Upgrade to 7.23.6 or 7.24.3 and verify the running version.
- Baseline the outbound destinations each device contacts, then alert on new or changed endpoints.
- Log and review certificate validation failures rather than discarding them.
- Bound management access to trusted networks so a redirection failure is not also a credential exposure.
- Treat 7.23.4 and 7.24.2 as unpatched in monitoring and inventory.
References
- CERT Polska advisory on MikroTik RouterOS vulnerabilities: https://cert.pl/posts/2026/09/mikrotik-routeros-cve/
- CERT Polska technical analysis of the RouterOS disclosure process: https://cert.pl/posts/2026/09/mikrotick-analiza-techniczna/
Top comments (0)