Mikrotik SSH Vulnerability 6.14+

https://twitter.com/hackerfantastic/status/1065838886989922305

Once again, Mikrotik’s custom implementation (instead of a well-tested open source version) has introduced a security flaw:


The take-away from this is that an attacker could perform a MITM attack against any Mikrotik router during the initial SSH2 negotiation (providing the admin uses a client supporting “none” ciphers) and disable encryption - exposing plain-text passwords and other sensitive data.

UPDATE: The researcher has retracted this claim: https://twitter.com/hackerfantastic/status/1066020519068090369

Your provided link does not work. Do you have any other resources?

6.14?
Do you mean 6.41?

It looks like the researcher has retracted their claim. The only remaining issue is that the sshd supports a “null” cipher, which isn’t secure - but you have to explicitly ask for it.

https://twitter.com/hackerfantastic/status/1066020519068090369

I imagine a lot of eyes are on MikroTik related possibilities at this time. Stay safe folks.