GPU VulnDB

Database/Firmware, BMC & network fabric

MikroTik RouterOS: SSH username argument handling lets an unauthenticated client escalate policy privileges

CVSS 9.2CVE-2026-86060Firmware, BMC & network fabricKnown exploitedcurated

Impact

An argument-handling flaw in the SSH login path lets a username beginning with a prohibited character alter the trusted RouterOS policy mask, escalating privilege from an unauthenticated SSH session. RouterOS devices frequently sit on the management or out-of-band network in front of a fleet, so a compromised router gives an attacker a foothold that sees BMC traffic, management VLANs and the paths used to provision nodes. CERT.pl reports this is being actively exploited and it is in the CISA KEV catalogue. Anyone who can open a TCP session to the SSH port is in range.

Who can reach it

Anyone who can reach the device's SSH service - typically the management network, or the internet if SSH is exposed. No authentication required; the flaw is in the pre-auth login helper.

What to do

Upgrade RouterOS to 6.49.21 (Long-term), 7.23.4 (Long-term) or 7.24.2 (Stable). The upgrade reboots the device, so the link it carries drops for the duration - schedule around it or fail traffic over first. Until upgraded, restrict SSH to a trusted management source or disable the SSH service. Given active exploitation, also inspect the device for added users, changed policy groups and scheduler scripts after patching.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.