{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "698bd7a2f68e63265fae67660e32bfeab8939e095a5b28f4753c1101be32e941",
    "authored_runtime_manifest_sha256": "99697567ada6f0286ea4f5a9f54b3cb3465019c17a45c777d34a962ef245b2be",
    "authored_verdict_sha256": "dc749034e689866b8d0104ae979c1965a860fc66c0659c568dc7317a9a7b09c7",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "20f62cfe-77dd-40dd-8fc1-57801d5e2ba0"
  ],
  "attacker_controlled_input": "RouterOS username plus forged SSH RSA public key/signature using the authorized modulus and attacker-selected exponent e=1",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "authz_bypass",
  "claimed_surface": "network_protocol",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "authz_bypass",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "TCP SSH userauth-publickey to the real RouterOS CHR SSH service, followed by an SSH exec channel",
  "validated_surface": "network_protocol"
}
