https://twitter.com/hackerfantastic/status/1065838886989922305
Once again, Mikrotik’s custom implementation (instead of a well-tested open source version) has introduced a security flaw:
The take-away from this is that an attacker could perform a MITM attack against any Mikrotik router during the initial SSH2 negotiation (providing the admin uses a client supporting “none” ciphers) and disable encryption - exposing plain-text passwords and other sensitive data.
UPDATE: The researcher has retracted this claim: https://twitter.com/hackerfantastic/status/1066020519068090369