<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>0day on Sijisu</title><link>https://sijisu.eu/tags/0day/</link><description>Recent content in 0day on Sijisu</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 25 Sep 2026 13:37:00 +0100</lastBuildDate><atom:link href="https://sijisu.eu/tags/0day/index.xml" rel="self" type="application/rss+xml"/><item><title>Finding 3 MikroTik pre-auth RCEs</title><link>https://sijisu.eu/posts/3-mikrotik-preauth-rces/</link><pubDate>Fri, 25 Sep 2026 13:37:00 +0100</pubDate><guid>https://sijisu.eu/posts/3-mikrotik-preauth-rces/</guid><description>&lt;p&gt;This is the story of GPT 5.6 Sol, DeepSeek v4 Flash 0731, and me finding three pre-authentication RCEs in MikroTik RouterOS.&lt;/p&gt;&#10;&lt;h2 id="tldr"&gt;TL;DR&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;LLMs found &lt;strong&gt;2 pre-auth exploitable bugs on the MikroTik RouterOS 7.23.3&lt;/strong&gt;, both resulting in RCE under some conditions&#10;&lt;ul&gt;&#10;&lt;li&gt;DHCP relay buffer overflow&lt;/li&gt;&#10;&lt;li&gt;WebFig auth bypass resulting in file upload, resulting in delayed RCE&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;they achieved this without any special harnesses, &lt;strong&gt;just a /goal prompt&lt;/strong&gt; inspired by the one that found wp2shell&lt;/li&gt;&#10;&lt;li&gt;the SSH RCE exploited in the wild was not found in this research, because it was not included in the pre-auth scope during the initial run&#10;&lt;ul&gt;&#10;&lt;li&gt;ensuring &lt;em&gt;all&lt;/em&gt; vulnerabilities have been found is still hard&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;after MikroTik patched we found &lt;strong&gt;another pre-auth RCE&lt;/strong&gt; utilizing a session takeover&#10;&lt;ul&gt;&#10;&lt;li&gt;AES-CTR vulnerable in WebFig resulting in unauthenticated file upload&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;GPT 5.6 Sol is &lt;strong&gt;extremely capable&lt;/strong&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;you don&amp;rsquo;t need a harness, just a manager who &amp;ldquo;kinda knows what he is doing&amp;rdquo;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;you should &lt;strong&gt;update everything as soon as possible&lt;/strong&gt; every time&#10;&lt;ul&gt;&#10;&lt;li&gt;every outdated software should be automatically considered exploitable by &lt;em&gt;anyone&lt;/em&gt;&lt;/li&gt;&#10;&lt;li&gt;every updated software only a little bit less exploitable&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;this is still only the beginning, I&amp;rsquo;m certain there are &lt;strong&gt;many more, even worse, bugs to be discovered&lt;/strong&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="deepseek-v4-flash-attempt"&gt;Deepseek v4 Flash attempt&lt;/h2&gt;&#10;&lt;p&gt;When DeepSeek v4 Flash 0731 came out at the beginning of August, it seemed almost &lt;em&gt;free&lt;/em&gt; to use - it barely consumed any usage while still being quite powerful.&lt;/p&gt;</description></item></channel></rss>