MikroTik's Silent Patch: How a Username of '-2' Grants Full RouterOS Admin
Reversing MikroTik's Silent Patch: The RouterOS 7.23.4 Fix They Wouldn't Explain
On September 3, 2026, MikroTik silently patched a critical SSH vulnerability across all RouterOS branches, withholding details. By diffing the binaries, a researcher uncovered two flaws: a low-exponent RSA signature forgery and a legacy file-descriptor login transport. The latter allows an authenticated read-only SSH session to inject a full policy mask via a username of '-2', escalating to full command execution. The patch adds input validation, but a credential-free initial access vector remains unknown.
If you ship the fixed binaries to the entire planet, then the diff between old and new is the disclosure.