VDB

GCVE-110-NCSC-2026-345

GCVE-110-NCSC-2026-345
Advisory Published
Vulnetix · Advisory published September 8, 2026
RouterOS 7.x contained a critical SSH authentication vulnerability where only the RSA key type and modulus were verified, ignoring the exponent, enabling signature forgery and unauthorized access, fixed in versions 7.23.4 and 7.24.2.

Weaknesses (CWE)

CWE-347Improper Verification of Cryptographic SignatureCWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')CWE-306Missing Authentication for Critical Function

Affected Products

VendorProductVersionsPlatforms
MikroTikvers:unknown/*

References

advisory
exploit
advisory
advisory
advisory
advisory

Browse GCVE Records

540 records in the GCVE database · Updated September 8, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›