CVE-2026-67276 CURRENT-RUN PRODUCTION-PATH RESULT entrypoint=tcp_peer service=real RouterOS CHR SSH over TCP via QEMU user networking attacker_inputs=username and authorized RSA public modulus only original_authorized_exponent=65537 attacker_offered_exponent=1 authorized_private_key_present=false vulnerable_7.23.3_attempt_1=forged_auth_accepted_and_command_channel_opened vulnerable_7.23.3_attempt_2=forged_auth_accepted_and_command_channel_opened fixed_7.23.4_attempt_1=forged_auth_rejected_before_command_channel fixed_7.23.4_attempt_2=forged_auth_rejected_before_command_channel observed_impact=authz_bypass scope_note=no privilege escalation or other CVE was attempted