Skip to finding
§
High
Edge — RouterOS
Confirmed
CVE-2026-67278

An on-path attacker can forge certificates that RouterOS accepts for any TLS server.

The attack needs control or redirection of a RouterOS-initiated TLS connection and the public certificate of a trusted RSA root using exponent 3.

Affects

MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.

What it enables

Impersonation of arbitrary TLS servers to RouterOS without a trusted CA private key

Obtain an on-path or traffic-redirection position for a RouterOS-initiated TLS connection→↓Use the public certificate of an e=3 root already present in the RouterOS trust store→↓Forge a certificate chain exploiting incomplete PKCS#1 v1.5 signature validation→↓Present a certificate for an attacker-chosen server name→↓RouterOS accepts the attacker as the intended TLS server
Why this matters

This removes trusted-authority authentication from every outbound TLS service that relies on the affected RouterOS certificate check.

Detail and 3 sources
Required access

Control or redirection of an outbound TLS connection initiated by an affected RouterOS device

Affected versions

6.0.0 before 6.49.21, 7.0.0 before 7.23.4, 7.24 before 7.24.2

Proof of concept

Demonstrated by the researcher

CERT Polska validated the certificate-forgery behavior on real RouterOS systems.

Incomplete PKCS#1 v1.5 validation lets the attacker forge a chain under the trusted root, name an arbitrary server, and have RouterOS accept it as the intended peer.

Fixed release ranges are public and complete revocation on updated supported systems; pre-fix images still accept the forged chains, and the fixes do not reach end-of-life hardware.

Evidence
CERT Polska identifies the trusted e=3 root, incomplete RSA/PKCS#1 v1.5 validation, and arbitrary-name certificate consequenceCERT Polska reports validation of the findings on real RouterOS systemsFixed RouterOS release ranges are publicly available
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 7, 2026