
Keys and encryption
SSH and RSA keys, signatures, encryption, certificate validation: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

RSA Key Verification Flaw in SSH Server
RouterOS does not compare the RSA public key exponent during SSH authentication, allowing an attacker to forge valid signatures if they know the modulus of an authorized key. This issue affects 7.x versions prior to 7.23.4 and 7.24.2. You must update the firmware or restrict access to the SSH service to trusted networks only.
SecurityFlawed RSA Signature in RouterOS: CVE-2026-67278
CVE-2026-67278 is a critical vulnerability (CVSS 9.1) that allows an attacker to forge TLS certificates and SSH authentications on MikroTik RouterOS routers. It affects 7.x versions prior to 7.23.6 and 7.24.3; releases 7.23.4 and 7.24.2 contain an incomplete fix. To protect yourself, immediately update to one of the fixed versions or disable RSA services exposed to untrusted networks.
SecurityVulnerabilità path traversal in WinBox
CVE-2020-5720 è una vulnerabilità di path traversal in WinBox, il client grafico per la gestione dei router MikroTik. Colpisce tutte le versioni di WinBox precedenti alla 3.21 e permette la creazione di file arbitrari se il client si connette a un endpoint malevolo o subisce un attacco man-in-the-middle. Per mitigare il rischio è necessario aggiornare WinBox alla versione 3.21 o superiore e limitare l'accesso al servizio solo dalla rete di amministrazione fidata.
SecurityVulnerabilità nella validazione certificati RouterOS
CVE-2025-42611 è una vulnerabilità di validazione dei certificati che può consentire il bypass dell'autenticazione in servizi come OpenVPN, CAPsMAN e Dot1X. Colpisce le versioni di RouterOS fino a 7.20.x. La versione correttiva non è ancora comunicata; alla data dell'articolo la vulnerabilità non risulta sfruttata attivamente.