Repository author dinosn published the MikroTrick lab PoC for CVE-2026-67276, which shows a RouterOS SSH authentication bypass.

The analysis says RouterOS matches an SSH key by type and RSA modulus, but does not check the exponent. The attack therefore needs only the victim’s known public modulus, not the private key.

In a lab test, the author authenticated and ran a command on RouterOS 7.23.3. RouterOS 7.23.4 rejected the forged key.

The repository advises updating RouterOS to a fixed version. Until then, it suggests restricting SSH, WWW, and bandwidth-test to trusted management networks.

Terms:

  • PoC — Proof of Concept, or a working demonstration. In security, this means an example that shows how to reproduce a vulnerability.
  • RSA modulus — A part of a public RSA key. It is used in cryptographic checks and is usually available with the public key.
  • exponent — An RSA key parameter used in cryptographic calculations. It is stored with the modulus in the public key.

Claim check:

  • In the context of the MikroTrick incident, repository author dinosn published a lab PoC for CVE-2026-67276 that shows a RouterOS SSH authentication bypass. (confirmed by the publication itself: evidence; «MikroTrick lab PoC — CVE-2026-67276 (RouterOS SSH public-key auth bypass)»)
  • The repository states that on September 5, 2026, CERT PL disclosed six actively exploited RouterOS vulnerabilities collectively called MikroTrick. (confirmed by the publication itself: evidence; «CERT PL (2026-09-05) disclosed six RouterOS vulnerabilities, actively exploited in the wild as the chain “MikroTrick” (unauthenticated full device takeover when SSH is internet-reachable).»)
  • According to the PoC analysis, in CVE-2026-67276 RouterOS matches an SSH key by type and RSA modulus, but does not check the exponent. (confirmed by the publication itself: evidence; «RouterOS matches the presented SSH public-key blob against the user’s authorized key by (key type, modulus) — the exponent is not compared.»)
  • The PoC relies on signature verification using the client-supplied key: with a key whose exponent is e=1, the attack needs only the victim’s known public modulus, not the private key. (confirmed by the publication itself: evidence; «Presenting {ssh-rsa, e=1, n=victim} makes sig^1 mod n == sig , so the valid “signature” is simply EMSA-PKCS1-v1_5(hash, authdata) — computable by anyone who knows the victim’s public modulus. No private key needed.»)
  • For reproduction, the author lists an SSH-accessible device in the affected range, a username, and the RSA modulus of its authorized key as requirements. (confirmed by the publication itself: evidence; «Preconditions (the disclosure’s own minimum): target username + that user’s authorized RSA public modulus.»)
  • In the cited lab retest, a forged key with e=1 authenticated and ran a command on RouterOS 7.23.3, while the fixed 7.23.4 rejected it. (confirmed by the publication itself: evidence; «7.23.3 auth OK auth OK + /system resource print exec — CVE confirmed 7.23.4 (patched) auth OK rejected»)
  • The author also notes that RouterOS 6.49.20 rejected the key with e=1 in the test, so the observed vulnerability was not confirmed for this version despite the range stated by CERT. (confirmed by the publication itself: evidence; «Version nuance: on 6.49.20 the server-side match rejects the e=1 blob ( /log ssh,debug: can’t find matching key for user: admin ) — the disclosed exponent-omission was not observable in 6.x’s matcher although CERT’s blanket range lists [6.0.0, 6.49.21) .»)
  • As an immediate measure, the repository proposes updating RouterOS to 7.25beta3, 7.24.2, 7.23.4, or 6.49.21, and restricting access to SSH, WWW, and bandwidth-test to trusted management networks until the update. (confirmed by the publication itself: evidence; «Patch immediately: 7.25beta3 / 7.24.2 / 7.23.4 / 6.49.21. Interim: restrict SSH/WWW/bandwidth-test to trusted management networks; avoid RouterOS-initiated SSH/TLS from unpatched devices.»)

Primary sources:

score 81.3 · kind incident · revision 1 · stories st-xlr7vb