Impact
The vulnerability allows RouterOS to accept malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because the trust store contains a root CA with an exponent of 3, an attacker can craft a forged intermediate certificate using only the public portion of that root CA. This enables the attacker to issue certificates for arbitrary hostnames and perform TLS server impersonation against any TLS connection originating from the infected device.
Affected Systems
The affected product is Mikrotik RouterOS. The fix was released in firmware 6.49.21 (Long‑term), 7.23.4 (Long‑term) and 7.24.2 (Stable). Devices running earlier firmware versions are vulnerable. The vulnerability is not limited to a specific model; all RouterOS devices that contain the e=3 root CA in their trust store are susceptible if their firmware has not received these updates.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS is not available, so the public exploit probability cannot be quantified. It is not in the CISA KEV catalog. The attack vector is likely over the network: an attacker who can redirect or control outbound TLS traffic from the RouterOS device can supply the forged certificate chain; the device will accept it without requiring the private key of the root CA. Once authenticated, the attacker can intercept or alter traffic, achieving full TLS impersonation. No additional privileges are required beyond those normally granted to the RouterOS device's outbound traffic.
OpenCVE Enrichment