Settings

Theme

Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours

blog.tolmo.com

4 points by ecares · 4 comments

Reader

1 thread
smurda

“Exploitation started three days before the public advisory”

I think bug bounty programs are completely overwhelmed right now. Idk how people keep up with them.

  • ecaresOP

    They really don't. I was recently approached by a journalist working on a piece on that exact topic.

  • dns_snek

    Mikrotik doesn't have a bug bounty program and their handling of vulnerability reports has always been substandard.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection