Skip to content
Topic

SSH

SSH server and client, keys, remote console access: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per CVE-2026-67276
Security High · 8.1
CVE-2026-67276

RSA Key Verification Flaw in SSH Server

RouterOS does not compare the RSA public key exponent during SSH authentication, allowing an attacker to forge valid signatures if they know the modulus of an authorized key. This issue affects 7.x versions prior to 7.23.4 and 7.24.2. You must update the firmware or restrict access to the SSH service to trusted networks only.

3 min read
Illustrazione per CVE-2026-67278Security
CVE-2026-67278

Flawed RSA Signature in RouterOS: CVE-2026-67278

CVE-2026-67278 is a critical vulnerability (CVSS 9.1) that allows an attacker to forge TLS certificates and SSH authentications on MikroTik RouterOS routers. It affects 7.x versions prior to 7.23.6 and 7.24.3; releases 7.23.4 and 7.24.2 contain an incomplete fix. To protect yourself, immediately update to one of the fixed versions or disable RSA services exposed to untrusted networks.

Critical · 9.1
Illustrazione per CVE-2026-86060Security
CVE-2026-86060

Unauthorized command execution via SSH

CVE-2026-86060 is a critical vulnerability in the RouterOS SSH server that allows unauthenticated privilege escalation. It affects versions prior to 6.49.21, 7.23.4, and 7.24.2. It is listed in the CISA KEV catalog and must be patched immediately.

Critical · 9.8Exploited
Illustrazione per CVE-2026-67279Security
CVE-2026-67279

SSH Vulnerability in RouterOS: Unauthenticated Access

CVE-2026-67279 allows an unauthenticated client to open an SSH session and send exec requests, enabling the creation, overwriting, or reconstruction of files within the namespace managed by RouterOS. Versions prior to 6.49.21, 7.23.4, and 7.24.2 are affected. The vulnerability is listed in the CISA KEV catalog: you must update the firmware immediately.

Medium · 6.5Exploited
Illustrazione per Hardening di base di un router MikroTik con RouterOS 7Dojo
Howto · Security

Basic hardening of a MikroTik router with RouterOS 7

A MikroTik freshly reset with no-defaults=yes has no firewall: it is fine on the bench for learning, but it should never be put on the network like that. Before installing it, you need seven hardening steps: update RouterOS, replace the admin user, disable unused services and restrict the others to authorized addresses, close service ports on external interfaces, a minimal firewall that blocks everything coming from the internet, and a VPN for remote management.

Illustrazione per Denial of Service nel server SSH di RouterOSSecurity
CVE-2020-20021

Denial of Service in the RouterOS SSH Server

CVE-2020-20021 is a Denial of Service (DoS) vulnerability affecting the SSH server in MikroTik Router v6.46.3 and earlier versions. A remote attacker can cause a service interruption by exploiting a misconfigured SSH daemon. To mitigate the risk, you must update the firmware to a later version or restrict access to the SSH service to the trusted administration network only.

High · 7.5
Illustrazione per CVE-2020-10364Security
CVE-2020-10364

Denial of Service in the SSH daemon

CVE-2020-10364 is a high-severity vulnerability that allows a remote attacker to cause a denial of service (DoS) on the router, generating excessive CPU activity and potential reboots. It affects systems with the SSH daemon active and reachable from untrusted networks. The primary mitigation is to restrict access to the SSH service to the administration network only or disable it if not required.

High · 7.5