Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-mikrotik-poc — CVE-2026-86060 - CVE-2026-67279 - CVE-2026-67276 RouterOS SSH | Kitploit
أدوات/GitHubGitHub/gagaltotal/cve-2026-mikrotik-poc
Embedded Systems SecurityVulnerability AnalysisExploitationNetwork SecurityPenetration TestingAuthenticationLearning & EducationRed Teaming
GitHubgagaltotal/cve-2026-mikrotik-poc

CVE-2026-mikrotik-poc

CVE-2026-86060 - CVE-2026-67279 - CVE-2026-67276 RouterOS SSH

عرض المستودع
19منذ 6 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

MikroTik RouterOS PoC Collection

This repository contains proof-of-concept (PoC) scripts for several MikroTik RouterOS security issues researched and documented in 2026. The materials are intended for authorized security research, laboratory validation, and controlled testing only.

This project is not a production application, not a general-purpose tool, and not intended for use against systems without explicit authorization.

Scope

The collection currently includes:

  • CVE-2026-86060

    • Unauthenticated SSH session policy-mask swap / full-admin takeover path
    • Provided as a standalone PoC script
  • CVE-2026-67276

    • SSH public-key authentication bypass PoC for affected RouterOS builds
    • Includes its helper component for signature forgery

Repository Layout

CVE-2026-mikrotik-poc/
├── README.md
├── .gitignore
├── CVE-2026-86060.py
├── CVE-2026-67276/
│   ├── CVE-2026-67276.py
│   ├── forge_67276.py
│   └── ...
└── .venv/                  # local environment, typically excluded from git

Important Notice

This repository is for:

  • authorized red-team exercises
  • internal security validation
  • research in isolated lab environments
  • understanding disclosed vulnerabilities in a controlled setting

This repository must not be used against public or third-party infrastructure without proper authorization and legal review.

Requirements

The scripts are Python-based and require:

  • Python 3
  • pip
  • Paramiko

Install the dependency with:

python3 -m pip install paramiko

Getting Started

Clone the repository and enter the project directory:

git clone <repository-url>
cd CVE-2026-mikrotik-poc

Create a virtual environment if needed:

python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install --upgrade pip
python3 -m pip install paramiko

Usage Examples

CVE-2026-86060

Display the script's built-in help and options:

python3 CVE-2026-86060.py --help

Run the script against a lab target:

python3 CVE-2026-86060.py <router-ip>

CVE-2026-67276

Display the script's built-in help:

python3 CVE-2026-67276/CVE-2026-67276.py --help

Run the script in an authorized lab environment:

python3 CVE-2026-67276/CVE-2026-67276.py --host <router-ip> --user <username>

Notes

  • These scripts are proof-of-concept implementations and may not be production-safe.
  • Behavior can vary depending on RouterOS version, configuration, and environment.
  • Some scripts rely on helper files kept in the same directory or on PYTHONPATH.
  • The repository is intentionally minimal and focused on reproducibility in lab environments.

Security and Ethical Use

Use this repository responsibly and only in accordance with applicable laws, policies, and contractual obligations. It is the user's responsibility to ensure that all testing is authorized and isolated from production systems.

Disclaimer

This project is provided for educational and research purposes only. The authors do not condone unauthorized access or malicious use. All use must be limited to environments you own, operate, or are explicitly authorized to test.

Maintainer

This project was created for research and defensive learning, with code associated to public disclosure research around MikroTik RouterOS vulnerabilities.

تنزيل الأداة