RouterOS accepted forged TLS certificate chains without a trusted private key.
MikroTik RouterOS, the operating system used by MikroTik routers and wireless network appliances.
Malformed RSA/PKCS#1 v1.5 signatures and RouterOS's trusted exponent-three root let an attacker construct a forged intermediate and issue a certificate for the requested hostname.
Detail and 3 sources
CERT Polska confirmed the behavior on real systems with repetition and negative controls.
The attacker still needs destination control or an on-path redirection position.
Fixed releases close the path, but pre-fix images remain accepted and some affected hardware is already end of life.