- Attackers are exploiting a critical vulnerability in MikroTik RouterOS that grants full administrative control via SSH without authentication.
- Successful attacks have been observed since at least September 2, 2026, according to CERT Polska.
- MikroTik has released security fixes for RouterOS versions 6.49.21, 7.23.4, 7.24.2, and a development channel fix in 7.25beta3.
- CERT recommends immediate installation of updates and a thorough check for unauthorized configuration changes or new admin accounts.
Attackers are exploiting MikroTik routers by accessing their Secure Shell (SSH) remote service from the internet, gaining full administrative control without authentication, according to CERT Polska’s attack warning published September 5. The Hacker News’s September 6 review of the warning found no victim count or attacker identity, with successful attacks dating to at least September 2.
MikroTik’s security update lists fixed RouterOS releases, and CERT says these fixes prevent the observed attacks. The vendor’s default firewall explanation notes that home devices block public management ports while default rules remain intact.
CERT’s affected versions range from RouterOS 6.0.0 below 6.49.21 and from 7.0.0 below 7.23.4, among others, with initial fixes at 6.49.21, 7.23.4, and 7.24.2. The 7.23.5 regression fix addresses an IPv6 DHCP problem introduced in 7.23.4 while retaining the security update.
Until the update can be installed, CERT recommends turning off exposed services or restricting access to trusted management networks, particularly for SSH, WWW/WWW-SSL, and bandwidth-test. It also advises against initiating TLS connections or using RouterOS’s built-in SSH clients from an unpatched device.
MikroTik’s Flagged status guidance states that RouterOS flags a device when startup checks detect suspicious configuration, disabling those entries and restricting certain functions. After updating, check logs and run /system/device-mode/print to inspect that status, and look for unexpected highly privileged ops accounts or account-creation logs containing “ssh:-2@” as signs of compromise.
If compromise is suspected, CERT recommends isolating the router, preserving logs and configuration before resetting it, restoring factory settings with a trusted configuration, and changing all passwords and keys. CERT calls the reported 2-flaw combination MikroTrick, though neither CERT nor MikroTik explicitly identifies the specific vulnerabilities in the observed chain.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
