MikroTik schließt ausgenutzte Schwachstellen in RouterOS
Teaser aus der Quelle
Der Netzwerkhersteller MikroTik hat Patches für sechs Sicherheitslücken in seiner RouterOS-Firmware veröffentlicht, darunter zwei kritische Schwachstellen (CVE-2026-67276), die es Angreifern ermöglichen, Geräte ohne Authentifizierung über SSH zu übernehmen. Die Schwachstellen wurden von der CERT Polska entdeckt und sind bereits aktiv ausgenutzt. MikroTik empfiehlt dringend das Aktualisieren auf RouterOS 7.25 beta 3, 7.24.2, 7.23.4 oder 6.49.21 und rät davon ab, den SSH-Dienst im Internet-Interface zu aktivieren.
Dies ist ein Anriss aus dem RSS-Feed. Den vollständigen Artikel liest du beim Original.
Artikel bei CSO Online lesen →Verknüpfte Empfehlungen
- CVE-2026-67276cve.org:CVE-2026-67276
- CVE-2026-67276RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulu…
- CVE-2026-67276cvelistv5:CVE-2026-67276
- CVE-2026-86060MikroTik RouterOS — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login
- CVE-2026-86060cvelistv5:CVE-2026-86060
Mehr zu MikroTik
Weitere Empfehlungen
- bsi:WID-SEC-2026-3193criticalMikroTik RouterOS: Mehrere Schwachstellen
- CVE-2026-86060noneMikroTik RouterOS — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- CVE-2026-67277noneMikroTik RouterOS — MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- CVE-2026-67278noneMikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controll…
- CVE-2026-48695highFastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in s…
- CVE-2024-27686highMikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to t…
- CVE-2026-7668mediumA vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of th…
- osv:MAL-2025-39297noneMalicious code in winbox-mikrotik (npm)
Weitere News-Einträge
- Newssecurityweek2026-09-08MikroTik Patches Critical Flaws Chained to Hack Routers
- Newsncsc-nl2026-09-08NCSC-2026-0345 [1.00] [M/H] Kwetsbaarheden verholpen in MikroTik RouterOS
- Schwachstellebsi-cert-bund-wid2026-09-07MikroTik RouterOS: Mehrere Schwachstellen
- Newsbleepingcomputer2026-09-07Hackers exploit new MikroTik RouterOS flaws to hijack routers
- Newssans-isc-diary2026-09-06Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
- Newsthehackernews2026-09-06Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
- Newsgolem-securityMikrotik: Über 100.000 Router sind laufenden Angriffen ausgesetzt
- Newsheise-securityMikroTrick: RouterOS-Lücken werden aktiv ausgenutzt – jetzt patchen
ID