Impact
RouterOS SSH incorrectly processes a client‑requested rekey before authenticating the user. The server proceeds to the SSH connection stage, allowing an unauthenticated client to open a session channel and issue exec requests. The execution path permits the creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including critical support files that hold configuration and diagnostic data. As a result, an attacker can effectively modify system files without any authentication, compromising confidentiality, integrity, and potentially the availability of routing services.
Affected Systems
Vendors are MikroTik, product is RouterOS. All builds released before the security patches are vulnerable. The fix is provided in the following releases: 6.49.21 (Long‑term), 7.23.4 (Long‑term) and 7.24.2 (Stable). Any earlier versions of RouterOS are impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity vulnerability, and the EPSS value is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over SSH: an attacker initiates a connection, requests a rekey, then sends an exec command that results in file system modifications. The lack of authentication at the rekey point is the key weakness that allows this bypass.
OpenCVE Enrichment