Skip to finding
important · Wi-Fi — RouterOS

An authorized exponent-3 RSA public key is enough to forge RouterOS SSH authentication without its private key.

Affects

MikroTik RouterOS, the operating system used by MikroTik routers and CHR virtual routers.

The public exploit uses incomplete PKCS#1 v1.5 verification to construct a valid checked prefix, but it needs the exact exponent-3 key authorized for the account.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 5, 2026