CVE-2026-67279
Received Received - Intake

Unauthenticated File Manipulation in RouterOS SSH

Vulnerability report for CVE-2026-67279, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: CERT.PL

Description

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions:Β 6.49.21 (Long-term),Β 7.23.4 (Long-term)Β andΒ 7.24.2 (Stable)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-06
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
mikrotik routeros 6.49.21
mikrotik routeros 7.23.4
mikrotik routeros 7.24.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-841 The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in RouterOS SSH allows an unauthenticated client to open a session channel and send an exec request even without user authentication. The server then executes commands, enabling unauthorized file operations in the RouterOS managed file namespace, including configuration and diagnostic data files.

Detection Guidance

Detecting this vulnerability requires checking RouterOS versions for affected builds (prior to 6.49.21, 7.23.4, or 7.24.2). Use RouterOS commands like /system package print to list installed versions. Network scanning tools can identify RouterOS devices and their versions.

Impact Analysis

An attacker could exploit this to create, overwrite, or reconstruct files on the affected RouterOS device. This may lead to unauthorized configuration changes, data theft, or system compromise, potentially disrupting network operations or exposing sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access and modification of sensitive data, violating confidentiality and integrity requirements in GDPR and HIPAA. Organizations may face compliance violations, data breaches, and potential legal penalties if exploited.

Mitigation Strategies

Immediately update RouterOS to a fixed version (6.49.21, 7.23.4, or 7.24.2). Disable SSH access if not required. Restrict network access to RouterOS devices via firewall rules. Monitor for unauthorized file modifications or suspicious exec requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67279. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart