Skip to content
Topic

Authentication bypass

Access to services or resources without valid credentials: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per CVE-2018-14847: Recupero password in chiaro da user.dat su RouterOS v6
Lab
Lab · CVE-2018-14847

CVE-2018-14847: Recovering plaintext passwords from user.dat on RouterOS v6

We reproduced the CVE-2018-14847 vulnerability on RouterOS v6, confirming that an unauthenticated attacker can read the user.dat file and recover plaintext passwords due to a weak XOR transformation. The issue is fixed in versions 6.40.8, 6.42.11, and 6.49.7, where access to the file is denied.

2 min read
Illustrazione per CVE-2026-67276Security
CVE-2026-67276

RSA Key Verification Flaw in SSH Server

RouterOS does not compare the RSA public key exponent during SSH authentication, allowing an attacker to forge valid signatures if they know the modulus of an authorized key. This issue affects 7.x versions prior to 7.23.4 and 7.24.2. You must update the firmware or restrict access to the SSH service to trusted networks only.

High · 8.1
Illustrazione per CVE-2026-67278Security
CVE-2026-67278

Flawed RSA Signature in RouterOS: CVE-2026-67278

CVE-2026-67278 is a critical vulnerability (CVSS 9.1) that allows an attacker to forge TLS certificates and SSH authentications on MikroTik RouterOS routers. It affects 7.x versions prior to 7.23.6 and 7.24.3; releases 7.23.4 and 7.24.2 contain an incomplete fix. To protect yourself, immediately update to one of the fixed versions or disable RSA services exposed to untrusted networks.

Critical · 9.1
Illustrazione per CVE-2026-86060Security
CVE-2026-86060

Unauthorized command execution via SSH

CVE-2026-86060 is a critical vulnerability in the RouterOS SSH server that allows unauthenticated privilege escalation. It affects versions prior to 6.49.21, 7.23.4, and 7.24.2. It is listed in the CISA KEV catalog and must be patched immediately.

Critical · 9.8Exploited
Illustrazione per CVE-2026-67279Security
CVE-2026-67279

SSH Vulnerability in RouterOS: Unauthenticated Access

CVE-2026-67279 allows an unauthenticated client to open an SSH session and send exec requests, enabling the creation, overwriting, or reconstruction of files within the namespace managed by RouterOS. Versions prior to 6.49.21, 7.23.4, and 7.24.2 are affected. The vulnerability is listed in the CISA KEV catalog: you must update the firmware immediately.

Medium · 6.5Exploited
Illustrazione per CVE-2025-6443Security
CVE-2025-6443

VXLAN Vulnerability in RouterOS: CVE-2025-6443

CVE-2025-6443 is an improper access control vulnerability (CWE-284) in the VXLAN service of MikroTik RouterOS that allows a remote attacker, without authentication, to bypass access restrictions and reach internal network resources. Versions 7.15.3 and 7.16.2 are confirmed vulnerable by CVE.org, while NVD indicates all versions prior to 7.20; the exact fixed version has not yet been announced. Those using VXLAN on untrusted networks must update the firmware as soon as it becomes available and verify the service configuration.

Illustrazione per CVE-2019-3981Security
CVE-2019-3981

Winbox Vulnerability: Man-in-the-Middle Attack

CVE-2019-3981 is a vulnerability in MikroTik Winbox 3.20 and earlier that allows an attacker positioned between the client and the router to perform an authentication downgrade and retrieve the username and MD5-hashed password. The risk arises when Winbox is reachable from untrusted networks. To mitigate the risk, you must update Winbox to a version later than 3.20 and restrict access to the service to the administration network only.

Low · 3.7
Illustrazione per CVE-2019-15055Security
CVE-2019-15055

Path Traversal Vulnerability in RouterOS (CVE-2019-15055)

CVE-2019-15055 is a path traversal vulnerability that allows authenticated users to delete arbitrary files on MikroTik RouterOS systems. The attack can lead to the reset of credential storage, permitting access to the management interface as an administrator without authentication. You must update the firmware to a version later than the vulnerable releases indicated in the description.

Illustrazione per CVE-2025-42611Security
CVE-2025-42611

Certificate Validation Vulnerability in RouterOS

CVE-2025-42611 is a certificate validation vulnerability that may allow authentication bypass in services such as OpenVPN, CAPsMAN, and Dot1X. It affects RouterOS versions up to 7.20.x. The fixed version has not yet been announced; as of the article date, the vulnerability is not known to be actively exploited.

Medium · 6.5
Illustrazione per CVE-2019-3924Security
CVE-2019-3924

Interception vulnerability in RouterOS

CVE-2019-3924 is an interception vulnerability that allows a remote unauthenticated attacker to issue user-defined network requests to WAN and LAN clients, enabling firewall bypass or network scanning. Affected versions are long-term 6.42.11 and earlier, and stable 6.43.11 and earlier. To protect yourself, you must upgrade to a version later than those indicated.

High · 7.5