RouterOS
Software
26
MENTIONS
14
EPISODES
12
PODCASTS
Search complete. 26 mentions across 14 episodes found for "RouterOS".
Oct 7, 2026
Network Nightmares: Bad Cables, Speed Concerns & Router Security - S3 Ep7
J
2:04JeremyHOST
This week we're kind of going all in on networking.
J
2:07JeremyHOST
Routers, switches, ethernet cables, Wi-Fi, IP addresses, and all those wonderful moments when someone says, "The network is down." Coming up on the Tech News Report, we're talking about a critical Microtech RouterOS vulnerability, a maximum severity flaw affecting older D-Link routers.
J
2:25JeremyHOST
Yeah, remember D-Link? Uh, and another actively exploited vulnerability affecting Cisco's SD-WAN management platform.
J
2:33JeremyHOST
Then on the repair bench, we've got a couple of networking problems we're gonna look at.
J
2:52JeremyHOST
But first, let's find out what's happening in networking and security.
J
2:55JeremyHOST
It's time for this week's Tech News Report.
J
3:02JeremyHOST
First up this week, the Cybersecurity and Infrastructure Security Agency is warning organizations about a critical vulnerability affecting Microtech, uh, RouterOS.
J
3:11JeremyHOST
The vulnerability exists in the web management service and can potentially be exploited before, uh, a attacker even authenticates.
Plaud Isn't the Best AI Companion? Amazon's Astro Meets Sarah's Dog, Yikes!- Live With It
R
10:03Roger ChangGUEST
And they have their own OS.
R
10:05Roger ChangGUEST
It's called RouterOS, um, coincidentally enough.
R
10:09Roger ChangGUEST
Some people like it, some people aren't that over the moon on it.
R
10:12Roger ChangGUEST
But the great [laughs] thing about their routers is they're really solid.
Cyber Security News for October 1 2026 - Daily DefSec Brief
J
1:04Jerry BellHOST
Three, a single request to a microtic router's web interface can run code as root with no login.
J
1:10Jerry BellHOST
It's a different flaw from the SSH bugs attackers used on RouterOS last month.
J
1:15Jerry BellHOST
This one isn't known to be exploited yet.
J
1:18Jerry BellHOST
Expect that to change.
J
1:19Jerry BellHOST
Upgrade RouterOS and keep the web interface off of the internet.
J
1:23Jerry BellHOST
Four, TeamViewer's session permissions are supposed to limit what the person you let in can do.
J
1:29Jerry BellHOST
A flaw lets that person change those permissions as the session starts.
Cyber Mornings Daily - September 28th, 2026
S
12:45speaker_0HOST
So let's move from the upcoming deadline to the fires that are burning on the network right this second.
S
12:51speaker_0HOST
The remaining additions to Cease's KevCatalog involve Microsoft SharePoint and Microtech RouterOS.
S
12:58speaker_1HOST
Yeah, and both of these are showing clear evidence of active exploitation in the wild, and they both represent severe structural risks to an enterprise.
S
13:06speaker_1HOST
Let's start with SharePoint and CVE-2026-65660.
6 MINS LATER
S
19:28speaker_0HOST
Get the patches applied before the September 30th deadline.
S
19:31speaker_0HOST
And if you can't, aggressively monitor your WAF logs for anomalous UDP traffic.
S
19:36speaker_1HOST
And finally, your immediate drop-everything priorities for today are Microsoft SharePoint and MikroTik RouterOS.
S
19:42speaker_1HOST
Do not let that old spoofing classification lull you into a false sense of security with SharePoint.
Cyber Security News for September 28 2026 - Daily DefSec Brief
J
1:17Jerry BellHOST
Four, someone who never logged into a Micronic Router's SSH service can ask for a key renegotiation, land in a session anyway, and send commands that create or overwrite files on the router, including its configuration files.
J
1:31Jerry BellHOST
That one is being exploited and CESA says it changed with a RouterOS SSH login flaw from earlier this month to get in without credentials.
J
1:40Jerry BellHOST
Upgrade RouterOS and keep SSH reachable only from your management network.
J
1:45Jerry BellHOST
By the way, this isn't the first exploited SSH flaw on these routers just this month.
J
1:50Jerry BellHOST
Five, the WordPress core flaw that makes a site load a PHP file from outside of Steam with no account is being exploited too.
Zero-Click Exchange RCE, $25 AI Intrusions, and the ShinyHunters FBI Claim
S
0:19Sean McMillanHOST
We'll look at a zero-click Exchange vulnerability that immediately jumped to the top of patch priority lists, a campaign where AI agents are autonomously compromising online retailers for about $25 a target, and ShinyHunters claim that it breached the FBI, not for money this time, but apparently for revenge.
S
0:40Sean McMillanHOST
And later in the show, I'll sit down with Bishop Fox adversarial operator Emilio Gallegos to unpack his microtrick research, uh, the RouterOS exploit chain that attackers were already using before defenders even knew it existed, and what organizations should be checking for now.
S
0:59Sean McMillanHOST
This is Initial Access.
S
1:01Sean McMillanHOST
[intro music] I'm Sean McMillan, community manager here at Bishop Fox, and I'm joined today by Kendrick Urbaniak, senior operator exploit developer, and Sergio Villegas, senior managing analyst.
37 MINS LATER
E
38:32Emilio GallegosGUEST
[laughs]
S
38:32Sean McMillanHOST
Yeah.
E
38:32Emilio GallegosGUEST
It's CVEA, which ends in 67279, um, essentially is a failure in that sequence because on a vulnerable RouterOS build, um, even though it, it never really asks you for authentication, you can request a process that is known as rekey, where essentially you're negotiating a new set of keys.
E
38:57Emilio GallegosGUEST
[chuckles] And the server, when you initiate that process, it sort of takes you to the next step, which allows you to essentially open, like, a new session channel.
Cyber Daily News for September 25th, 2026
S
0:44speaker_0HOST
If you run Roundcube, patching this is a tonight job, not a this week one.
S
0:49speaker_0HOST
Mikrotik shipped a quiet RouterOS update earlier this month, calling it important without saying what it fixed.
S
0:55speaker_0HOST
That silence did not hold.
S
0:57speaker_0HOST
Researchers with an assist from AI chained two of the patched flaws into an attack they named Microtrick that bypasses authentication and hands over full administrator control.
SANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details
J
2:40Johannes UllrichHOST
If you're interested in more details, uh, please refer to the Aikido blog.
J
2:45Johannes UllrichHOST
And the Polish CERT has published a detailed writeup regarding two vulnerabilities that Microtik recently patched in its RouterOS.
J
2:56Johannes UllrichHOST
If you remember, I talked about this when it was first reported that there was a vulnerability in Microtik's RouterOS, specifically in the SH demon that is delivered as part of RouterOS, that allowed for an authentication bypass via SH and complete compromise of the router.
J
3:17Johannes UllrichHOST
Now, Microtik did release patches, but no details about what exactly happened.
J
3:22Johannes UllrichHOST
The Polish CERT is now filling this gap, and they discovered two distinct vulnerabilities.
J
3:50Johannes UllrichHOST
Well, it turns out that that actually redirects the input, uh, to the SH demon from the client, so that's another part here of the authentication, uh, bypass.
J
4:01Johannes UllrichHOST
Interesting writeup, and definitely if you're running Microtik, make sure you're up to date.
J
4:06Johannes UllrichHOST
Uh, remember, this was also an SH demon that's unique to Microtik, so this is not a standard SH implementation like DropBear or OpenSH that they're deploying as part of RouterOS.
PP127: Network Configuration and State Visibility at Scale with Unimus (Sponsored)
T
11:13Tomas KirnakGUEST
And this affected even our infrastructure and it was even our own workflow.
T
11:18Tomas KirnakGUEST
Uh, and, and lots of customers use it too, is, uh, there, there was a security vulnerability, like a 9.2 CVSS, uh, vulnerability in MikroTik's RouterOS.
T
11:29Tomas KirnakGUEST
And I love MikroTik, it's nothing against MikroTik.
T
11:31Tomas KirnakGUEST
Like this happens all the time to Cisco, Juniper, to everyone.
12 MINS LATER
D
23:20Drew Connery-MurrayHOST
Okay.
D
23:21Drew Connery-MurrayHOST
How about network automation? It sounds like there's probably some good tie-in with network automation workflows and automation systems with Unimus.
T
23:28Tomas KirnakGUEST
Yeah, and, uh, even so w- with other examples of, of this CVE on, on MikroTik's RouterOS, right?
D
23:35Drew Connery-MurrayHOST
Mm-hmm.
Mikrotik and Cisco Active Exploits - The 443 Podcast - Episode 387
M
6:53Marc LaliberteHOST
Like, most, uh, networking equipment is typically built off Linux.
M
6:57Marc LaliberteHOST
You've got some other folks like Cisco that have their own operating system, but I'm willing to bet that RouterOS, which is their operating system, is probably built on Linux or Unix.
M
7:08Marc LaliberteHOST
Those have very standard libraries for handling SSH and handling SSH authentication, and this sounds like they rolled their own crypto or at least their own authentication library to introduce this issue.
M
7:20Marc LaliberteHOST
'Cause I'm not aware of any, like, open SSH or OpenSSL or, like, any AuthD issues that could have caused this.
M
7:41Marc LaliberteHOST
Yep.
M
7:42Marc LaliberteHOST
Uh, another issue, CVE-2026-86060, which was a SSH session privilege, uh, manipulation issue.
M
7:51Marc LaliberteHOST
Basically, uh, it sounds like RouterOS doesn't, uh, handle usernames that start with invalid characters during the SSH login well enough, and attackers can basically use a specially crafted username to gain additional privileges on the system.
M
8:08Marc LaliberteHOST
When you look at the actual CVE and some of the IoCs they gave, um, it, they show, like, negative two as the user authenticating.
4 more episodes mention RouterOS.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.