Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours
blog.tolmo.com
1 thread
“Exploitation started three days before the public advisory”
I think bug bounty programs are completely overwhelmed right now. Idk how people keep up with them.
They really don't. I was recently approached by a journalist working on a piece on that exact topic.
Any insights?
Mikrotik doesn't have a bug bounty program and their handling of vulnerability reports has always been substandard.