Description
MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation.

This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Published: 2026-09-05
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows RouterOS to accept malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because the trust store contains a root CA with an exponent of 3, an attacker can craft a forged intermediate certificate using only the public portion of that root CA. This enables the attacker to issue certificates for arbitrary hostnames and perform TLS server impersonation against any TLS connection originating from the infected device.

Affected Systems

The affected product is Mikrotik RouterOS. The fix was released in firmware 6.49.21 (Long‑term), 7.23.4 (Long‑term) and 7.24.2 (Stable). Devices running earlier firmware versions are vulnerable. The vulnerability is not limited to a specific model; all RouterOS devices that contain the e=3 root CA in their trust store are susceptible if their firmware has not received these updates.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. EPSS is not available, so the public exploit probability cannot be quantified. It is not in the CISA KEV catalog. The attack vector is likely over the network: an attacker who can redirect or control outbound TLS traffic from the RouterOS device can supply the forged certificate chain; the device will accept it without requiring the private key of the root CA. Once authenticated, the attacker can intercept or alter traffic, achieving full TLS impersonation. No additional privileges are required beyond those normally granted to the RouterOS device's outbound traffic.

Generated by OpenCVE AI on September 5, 2026 at 21:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RouterOS firmware to at least 6.49.21, 7.23.4, or 7.24.2 to apply the vendor fix.
  • Modify the trust store to remove or disable the root CA with exponent 3, ensuring no weak public exponent is trusted by the device.
  • Implement network monitoring and filtering to detect abnormal TLS connections originating from the RouterOS device, restricting outbound TLS traffic to trusted destinations only.

Generated by OpenCVE AI on September 5, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. This issue was fixed in versions: 6.49.21 (Lont-term), 7.23.4 (Lont-term) and 7.24.2 (Stable) MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Sat, 05 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. This issue was fixed in versions: 6.49.21 (Lont-term), 7.23.4 (Lont-term) and 7.24.2 (Stable)
Title TLS server impersonation possible in Mikrotik RouterOS
First Time appeared Mikrotik
Mikrotik routeros
Weaknesses CWE-347
CPEs cpe:2.3:a:mikrotik:routeros:*:*:*:*:*:*:*:*
Vendors & Products Mikrotik
Mikrotik routeros
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mikrotik Routeros
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-05T20:40:10.587Z

Reserved: 2026-07-29T11:59:30.538Z

Link: CVE-2026-67278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T20:17:18.257

Modified: 2026-09-05T21:16:50.503

Link: CVE-2026-67278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T22:30:17Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature