Database/Firmware, BMC & network fabric
MikroTik RouterOS: SSH username argument handling lets an unauthenticated client escalate policy privileges
Impact
An argument-handling flaw in the SSH login path lets a username beginning with a prohibited character alter the trusted RouterOS policy mask, escalating privilege from an unauthenticated SSH session. RouterOS devices frequently sit on the management or out-of-band network in front of a fleet, so a compromised router gives an attacker a foothold that sees BMC traffic, management VLANs and the paths used to provision nodes. CERT.pl reports this is being actively exploited and it is in the CISA KEV catalogue. Anyone who can open a TCP session to the SSH port is in range.
Who can reach it
Anyone who can reach the device's SSH service - typically the management network, or the internet if SSH is exposed. No authentication required; the flaw is in the pre-auth login helper.
What to do
Upgrade RouterOS to 6.49.21 (Long-term), 7.23.4 (Long-term) or 7.24.2 (Stable). The upgrade reboots the device, so the link it carries drops for the duration - schedule around it or fail traffic over first. Until upgraded, restrict SSH to a trusted management source or disable the SSH service. Given active exploitation, also inspect the device for added users, changed policy groups and scheduler scripts after patching.
References
Related entries
- Tripp Lite PDUMH15AT / SU750XL PDU: The PDU accepts unauthenticated POST requests to its /Forms/ endpoints, which canCVE-2019-16261 · Tripp Lite PDUMH15AT / SU750XL PDUCritical
- IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handling: The original default BMC password kept workingCVE-2019-4169 · IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handlingCritical
- Lanner IAC-AST2500A BMC firmware: An authenticated BMC user escalates to root code execution on the controllerCVE-2021-26731 · Lanner IAC-AST2500A BMC firmwareCritical
- Arista EOS (gNOI): gNOI APIs bypass authentication, allowing an unauthenticated factory reset of the switchCVE-2021-28506 · Arista EOS (gNOI)Critical
- APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signing: Firmware images are signed with a key that leakedCVE-2022-0715 · APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signingCritical
- AMI MegaRAC SPx12/SPx13: Insufficient verification of data authenticity — firmware image signature can be subvertedCVE-2023-28863 · AMI MegaRAC SPx12/SPx13Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.