Skip to main content
RouterOS

RouterOS

Software

Search complete. 26 mentions across 14 episodes found for "RouterOS".

Oct 7, 2026

JeremyHOST
2:04
This week we're kind of going all in on networking.
JeremyHOST
2:07
Routers, switches, ethernet cables, Wi-Fi, IP addresses, and all those wonderful moments when someone says, "The network is down." Coming up on the Tech News Report, we're talking about a critical Microtech RouterOS vulnerability, a maximum severity flaw affecting older D-Link routers.
JeremyHOST
2:25
Yeah, remember D-Link? Uh, and another actively exploited vulnerability affecting Cisco's SD-WAN management platform.
JeremyHOST
2:33
Then on the repair bench, we've got a couple of networking problems we're gonna look at.
JeremyHOST
2:52
But first, let's find out what's happening in networking and security.
JeremyHOST
2:55
It's time for this week's Tech News Report.
JeremyHOST
3:02
First up this week, the Cybersecurity and Infrastructure Security Agency is warning organizations about a critical vulnerability affecting Microtech, uh, RouterOS.
JeremyHOST
3:11
The vulnerability exists in the web management service and can potentially be exploited before, uh, a attacker even authenticates.
Roger ChangGUEST
10:03
And they have their own OS.
Roger ChangGUEST
10:05
It's called RouterOS, um, coincidentally enough.
Roger ChangGUEST
10:09
Some people like it, some people aren't that over the moon on it.
Roger ChangGUEST
10:12
But the great [laughs] thing about their routers is they're really solid.
Jerry BellHOST
1:04
Three, a single request to a microtic router's web interface can run code as root with no login.
Jerry BellHOST
1:10
It's a different flaw from the SSH bugs attackers used on RouterOS last month.
Jerry BellHOST
1:15
This one isn't known to be exploited yet.
Jerry BellHOST
1:18
Expect that to change.
Jerry BellHOST
1:19
Upgrade RouterOS and keep the web interface off of the internet.
Jerry BellHOST
1:23
Four, TeamViewer's session permissions are supposed to limit what the person you let in can do.
Jerry BellHOST
1:29
A flaw lets that person change those permissions as the session starts.
speaker_0HOST
12:45
So let's move from the upcoming deadline to the fires that are burning on the network right this second.
speaker_0HOST
12:51
The remaining additions to Cease's KevCatalog involve Microsoft SharePoint and Microtech RouterOS.
speaker_1HOST
12:58
Yeah, and both of these are showing clear evidence of active exploitation in the wild, and they both represent severe structural risks to an enterprise.
speaker_1HOST
13:06
Let's start with SharePoint and CVE-2026-65660.

6 MINS LATER

speaker_0HOST
19:28
Get the patches applied before the September 30th deadline.
speaker_0HOST
19:31
And if you can't, aggressively monitor your WAF logs for anomalous UDP traffic.
speaker_1HOST
19:36
And finally, your immediate drop-everything priorities for today are Microsoft SharePoint and MikroTik RouterOS.
speaker_1HOST
19:42
Do not let that old spoofing classification lull you into a false sense of security with SharePoint.
Jerry BellHOST
1:17
Four, someone who never logged into a Micronic Router's SSH service can ask for a key renegotiation, land in a session anyway, and send commands that create or overwrite files on the router, including its configuration files.
Jerry BellHOST
1:31
That one is being exploited and CESA says it changed with a RouterOS SSH login flaw from earlier this month to get in without credentials.
Jerry BellHOST
1:40
Upgrade RouterOS and keep SSH reachable only from your management network.
Jerry BellHOST
1:45
By the way, this isn't the first exploited SSH flaw on these routers just this month.
Jerry BellHOST
1:50
Five, the WordPress core flaw that makes a site load a PHP file from outside of Steam with no account is being exploited too.
Sean McMillanHOST
0:19
We'll look at a zero-click Exchange vulnerability that immediately jumped to the top of patch priority lists, a campaign where AI agents are autonomously compromising online retailers for about $25 a target, and ShinyHunters claim that it breached the FBI, not for money this time, but apparently for revenge.
Sean McMillanHOST
0:40
And later in the show, I'll sit down with Bishop Fox adversarial operator Emilio Gallegos to unpack his microtrick research, uh, the RouterOS exploit chain that attackers were already using before defenders even knew it existed, and what organizations should be checking for now.
Sean McMillanHOST
0:59
This is Initial Access.
Sean McMillanHOST
1:01
[intro music] I'm Sean McMillan, community manager here at Bishop Fox, and I'm joined today by Kendrick Urbaniak, senior operator exploit developer, and Sergio Villegas, senior managing analyst.

37 MINS LATER

Emilio GallegosGUEST
38:32
[laughs]
Sean McMillanHOST
38:32
Yeah.
Emilio GallegosGUEST
38:32
It's CVEA, which ends in 67279, um, essentially is a failure in that sequence because on a vulnerable RouterOS build, um, even though it, it never really asks you for authentication, you can request a process that is known as rekey, where essentially you're negotiating a new set of keys.
Emilio GallegosGUEST
38:57
[chuckles] And the server, when you initiate that process, it sort of takes you to the next step, which allows you to essentially open, like, a new session channel.
speaker_0HOST
0:44
If you run Roundcube, patching this is a tonight job, not a this week one.
speaker_0HOST
0:49
Mikrotik shipped a quiet RouterOS update earlier this month, calling it important without saying what it fixed.
speaker_0HOST
0:55
That silence did not hold.
speaker_0HOST
0:57
Researchers with an assist from AI chained two of the patched flaws into an attack they named Microtrick that bypasses authentication and hands over full administrator control.
Johannes UllrichHOST
2:40
If you're interested in more details, uh, please refer to the Aikido blog.
Johannes UllrichHOST
2:45
And the Polish CERT has published a detailed writeup regarding two vulnerabilities that Microtik recently patched in its RouterOS.
Johannes UllrichHOST
2:56
If you remember, I talked about this when it was first reported that there was a vulnerability in Microtik's RouterOS, specifically in the SH demon that is delivered as part of RouterOS, that allowed for an authentication bypass via SH and complete compromise of the router.
Johannes UllrichHOST
3:17
Now, Microtik did release patches, but no details about what exactly happened.
Johannes UllrichHOST
3:22
The Polish CERT is now filling this gap, and they discovered two distinct vulnerabilities.
Johannes UllrichHOST
3:50
Well, it turns out that that actually redirects the input, uh, to the SH demon from the client, so that's another part here of the authentication, uh, bypass.
Johannes UllrichHOST
4:01
Interesting writeup, and definitely if you're running Microtik, make sure you're up to date.
Johannes UllrichHOST
4:06
Uh, remember, this was also an SH demon that's unique to Microtik, so this is not a standard SH implementation like DropBear or OpenSH that they're deploying as part of RouterOS.
Tomas KirnakGUEST
11:13
And this affected even our infrastructure and it was even our own workflow.
Tomas KirnakGUEST
11:18
Uh, and, and lots of customers use it too, is, uh, there, there was a security vulnerability, like a 9.2 CVSS, uh, vulnerability in MikroTik's RouterOS.
Tomas KirnakGUEST
11:29
And I love MikroTik, it's nothing against MikroTik.
Tomas KirnakGUEST
11:31
Like this happens all the time to Cisco, Juniper, to everyone.

12 MINS LATER

Drew Connery-MurrayHOST
23:20
Okay.
Drew Connery-MurrayHOST
23:21
How about network automation? It sounds like there's probably some good tie-in with network automation workflows and automation systems with Unimus.
Tomas KirnakGUEST
23:28
Yeah, and, uh, even so w- with other examples of, of this CVE on, on MikroTik's RouterOS, right?
Drew Connery-MurrayHOST
23:35
Mm-hmm.
Marc LaliberteHOST
6:53
Like, most, uh, networking equipment is typically built off Linux.
Marc LaliberteHOST
6:57
You've got some other folks like Cisco that have their own operating system, but I'm willing to bet that RouterOS, which is their operating system, is probably built on Linux or Unix.
Marc LaliberteHOST
7:08
Those have very standard libraries for handling SSH and handling SSH authentication, and this sounds like they rolled their own crypto or at least their own authentication library to introduce this issue.
Marc LaliberteHOST
7:20
'Cause I'm not aware of any, like, open SSH or OpenSSL or, like, any AuthD issues that could have caused this.
Marc LaliberteHOST
7:41
Yep.
Marc LaliberteHOST
7:42
Uh, another issue, CVE-2026-86060, which was a SSH session privilege, uh, manipulation issue.
Marc LaliberteHOST
7:51
Basically, uh, it sounds like RouterOS doesn't, uh, handle usernames that start with invalid characters during the SSH login well enough, and attackers can basically use a specially crafted username to gain additional privileges on the system.
Marc LaliberteHOST
8:08
When you look at the actual CVE and some of the IoCs they gave, um, it, they show, like, negative two as the user authenticating.

4 more episodes mention RouterOS.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.