Six MikroTik RouterOS Flaws Enable Unauthenticated SSH Access and File Disclosure
MikroTik patched six vulnerabilities in RouterOS releases earlier than 6.49.21, 7.23.4, and 7.24.2. CERT Polska reported flaws affecting SSH authentication and RSA signature validation, WebFig file access, the btest service, and SSH login privilege handling. The issues can permit unauthenticated remote SSH command execution, disclosure of root-owned files that may contain credentials, kernel restarts, privilege escalation, and TLS server impersonation.
- Technical details published for RouterOS btest memory-disclosure flaw
- Technical details published for RouterOS SSH key-authentication bypass


