MikroTik's Silent Patch: How a Username of '-2' Grants Full RouterOS Admin

Reversing MikroTik's Silent Patch: The RouterOS 7.23.4 Fix They Wouldn't Explain

On September 3, 2026, MikroTik silently patched a critical SSH vulnerability across all RouterOS branches, withholding details. By diffing the binaries, a researcher uncovered two flaws: a low-exponent RSA signature forgery and a legacy file-descriptor login transport. The latter allows an authenticated read-only SSH session to inject a full policy mask via a username of '-2', escalating to full command execution. The patch adds input validation, but a credential-free initial access vector remains unknown.

If you ship the fixed binaries to the entire planet, then the diff between old and new is the disclosure.
  1. semiquaver

    God damn this writing is just a string of pure claudeisms. I can’t see the actual content because I’m cringing so hard.

    Why not just post the info you want to convey and the prompt? It would be easier for everyone involved.

  2. realxrobau

    Nick and I were at AusNOG when this dropped. Yes it was generated by AI, but it has evolved over time, and there has been at least three revisions of it.

    The three different issues are a username called "-2", incorrectly parsing/validating certificates, and tftp paths.

    There's also a dhcpd issue that was just fixed in a new release

  3. a2ff6eeb0

    It's incredible that we can have full security writeups done without a human involved at all.

More from this day

2026-09-05