Skip to content
Topic

Certificates and TLS

Certificates, SCEP, TLS, HTTPS on router: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per CVE-2026-67278
Security Critical · 9.1
CVE-2026-67278

Flawed RSA Signature in RouterOS: CVE-2026-67278

CVE-2026-67278 is a critical vulnerability (CVSS 9.1) that allows an attacker to forge TLS certificates and SSH authentications on MikroTik RouterOS routers. It affects 7.x versions prior to 7.23.6 and 7.24.3; releases 7.23.4 and 7.24.2 contain an incomplete fix. To protect yourself, immediately update to one of the fixed versions or disable RSA services exposed to untrusted networks.

3 min read
Illustrazione per CVE-2025-61481Security
CVE-2025-61481

WebFig Exposed in Clear on RouterOS and SwOS

CVE-2025-61481 exposes the WebFig management interface of RouterOS v.7.14.2 and SwOS v.2.18 via unencrypted HTTP, allowing a man-in-the-middle attacker to inject JavaScript into the administrator's browser and intercept credentials. The vulnerability is classified as critical with a CVSS score of 10.0. To mitigate the risk, disable WebFig if not necessary or restrict access exclusively to the trusted management network.

Critical · 10.0
Illustrazione per CVE-2021-41987Security
CVE-2021-41987

Buffer overflow in the RouterOS SCEP server

CVE-2021-41987 is a critical vulnerability (CVSS 8.1) in the RouterOS SCEP server that allows remote code execution. It affects versions 6.46.8, 6.47.9, and 6.47.10. You must update the firmware to a later version not listed as vulnerable or disable the SCEP service if not in use.

High · 8.1
Illustrazione per CVE-2025-42611Security
CVE-2025-42611

Certificate Validation Vulnerability in RouterOS

CVE-2025-42611 is a certificate validation vulnerability that may allow authentication bypass in services such as OpenVPN, CAPsMAN, and Dot1X. It affects RouterOS versions up to 7.20.x. The fixed version has not yet been announced; as of the article date, the vulnerability is not known to be actively exploited.

Medium · 6.5
Illustrazione per CVE-2026-7668Security
CVE-2026-7668

Out-of-bounds read in SCEP Endpoint

CVE-2026-7668 is an out-of-bounds read vulnerability in the SCEP Endpoint component of RouterOS 6.49.8, exploitable remotely without authentication. It affects only version 6.49.8; the vendor recommends upgrading to the latest available v6.x or 7.x version. It is not known to be actively exploited and is not included in the CISA KEV catalog.

High · 7.3