| |
MikroTik released security updates for RouterOS 7.23.4, 7.24.2, and 6.49.21 without disclosing details, claiming the embargo protects unpatched systems. However, a researcher reverse-engineered the patched binaries to reveal three bugs: an RSA signature forgery vulnerability, an SSH username validation flaw that allows authenticated read-only users to escalate to full command execution, and related overflow issues. The vulnerabilities were identified by diffing the changelogs across versions and analyzing the SSH refactoring changes present in all three releases.
Read Full Article →
← More Tech news