Tech & AI News
Hacker News

Reversing MikroTik's Silent Patch: The RouterOS 7.23.4 Fix They Wouldn't Explain

MikroTik issued RouterOS 7.23.4, 7.24.2, and 6.49.21 on 3 September 2026 with an “important security update” notice but no specifics. Reverse-engineered binaries revealed three bugs: a low-exponent RSA signature forgery causing an mtget overflow, an SSH flaw where a username of –2 reaches a legacy file-descriptor login transport, and a resulting authenticated read-only session that can inject a full policy mask to execute commands. The only shared changelog entry is “ssh – refactor SSH internal processes and improved system stability,” linking the vulnerabilities to the SSH component.