Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours

4 pointsposted 12 hours ago
by ecares

2 Comments

smurda

11 hours ago

“Exploitation started three days before the public advisory”

I think bug bounty programs are completely overwhelmed right now. Idk how people keep up with them.

ecares

9 hours ago

They really don't. I was recently approached by a journalist working on a piece on that exact topic.