An on-path attacker can forge certificates that RouterOS accepts for any TLS server.
The attack needs control or redirection of a RouterOS-initiated TLS connection and the public certificate of a trusted RSA root using exponent 3.
MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.
Impersonation of arbitrary TLS servers to RouterOS without a trusted CA private key
This removes trusted-authority authentication from every outbound TLS service that relies on the affected RouterOS certificate check.
Detail and 3 sources
CERT Polska validated the certificate-forgery behavior on real RouterOS systems.
Incomplete PKCS#1 v1.5 validation lets the attacker forge a chain under the trusted root, name an arbitrary server, and have RouterOS accept it as the intended peer.
Fixed release ranges are public and complete revocation on updated supported systems; pre-fix images still accept the forged chains, and the fixes do not reach end-of-life hardware.
- proposed:access:network:on-path
- proposed; not yet curated
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Revocation complete
- Yes
- Reaches end-of-life hardware
- No
For revocationComplete, “yes” means the code fix is not revocation-dependent.