Impact
RouterOS contains an argument‑handling flaw in the SSH login process that is triggered by usernames beginning with a prohibited character. The flaw causes the trusted policy mask to be altered, enabling an attacker to change internal policy settings and elevate privileges on the device. This is an input validation error classified as CWE‑88.
Affected Systems
All Mikrotik RouterOS installations running firmware versions earlier than 6.49.21 (Long‑term 6.x), 7.23.4 (Long‑term 7.x), or 7.24.2 (Stable 7.x) remain vulnerable. Devices that expose the SSH service to outside networks or untrusted hosts are at risk.
Risk and Exploitability
The CVSS score of 9.2 places this flaw in the critical category. The EPSS score is < 1 %, suggesting a low overall exploitation probability, yet active exploitation reports exist and the vulnerability is listed in the CISA KEV catalog. Because an attacker only needs an unauthenticated SSH session and a specially crafted username, the barrier to entry is low, making the risk significant for exposed devices.
OpenCVE Enrichment