Hacker News·5 min read·hard

Reversing MikroTik's Silent Patch: The RouterOS 7.23.4 Fix They Wouldn't Explain

Y
ytch
Reversing MikroTik's Silent Patch: The RouterOS 7.23.4 Fix They Wouldn't Explain
AI Summary

Security researchers reverse-engineered a silent patch released by MikroTik for its RouterOS software. The analysis revealed critical vulnerabilities, including an SSH authentication flaw that could allow unauthorized command execution.

Why it matters

Silent security patches often leave systems vulnerable to attackers who can reverse-engineer the fix before users update, highlighting the risks of 'security by obscurity' in network infrastructure.

Dive DeeperCreate a free account to unlock

On the 3rd of September 2026, MikroTik quietly pushed RouterOS 7.23.4 (long-term), 7.24.2 (stable) and 6.49.21 (v6) all on the same day. Every one of them carried the same banner:

This is an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information.

Translation: “we found something nasty, we patched it, and we are not going to tell you what it is until enough of you have updated.” Fair enough. Except there is a delicious irony baked into that sentence. If you ship the fixed binaries to the entire planet, then the diff between old and new is the disclosure. The embargo protects the unpatched fleet, not the patched binary sitting on your download mirror.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in