important · Wi-Fi — RouterOS
An authorized exponent-3 RSA public key is enough to forge RouterOS SSH authentication without its private key.
Affects
MikroTik RouterOS, the operating system used by MikroTik routers and CHR virtual routers.
The public exploit uses incomplete PKCS#1 v1.5 verification to construct a valid checked prefix, but it needs the exact exponent-3 key authorized for the account.
Detail and 2 sources
The forgery works against RouterOS 7.23.3 and is rejected by 7.23.4.