Impact
RouterOS contains an argument‑handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper. This flaw permits an unauthenticated user to alter internal policy settings and elevate privileges on the device, potentially achieving full control. The description confirms that the attacker only needs to craft a malicious username, without any prior authentication.
Affected Systems
All Mikrotik RouterOS installations using firmware versions earlier than 6.49.21 (long‑term 6.x branch), 7.23.4 (long‑term 7.x branch) or 7.24.2 (stable 7.x branch) remain vulnerable. The vulnerability is not limited by deployment location but by firmware revision, so any device running an affected version and exposed to SSH traffic is at risk.
Risk and Exploitability
The CVSS score of 9.2 places this vulnerability in the high‑severity range, and although the EPSS score is currently unavailable, references report active exploitation. The KEV catalog does not list it yet, but the presence of real‑world attacks and the low barrier to entry—only an open SSH port and a specially crafted username—make the risk substantial. An attacker can reach the vulnerable path through a standard unauthenticated SSH connection, highlighting the importance of rapid remediation.
OpenCVE Enrichment