Exposed MikroTik SSH Flaw Lets Attackers Seize Router Admin Control

CERT Polska warns that attackers are exploiting publicly reachable MikroTik SSH to gain full administrative control without authentication, with assaults dating back to Sept 2; MikroTik RouterOS updates exist across affected versions and should be installed immediately from official sources, followed by checking for unauthorized changes. The advisory notes a two-flaw chain dubbed MikroTrick and urges disabling exposed services or restricting SSH/WWW management to trusted networks until patched. Do not use TLS or the built-in SSH on unpatched devices, and monitor logs for signs of compromise (e.g., unknown users or ssh:-2@ entries). After updating, verify the device-mode status and examine logs; if compromised, isolate the router, preserve logs, reset to factory, and recreate configuration from a trusted source rather than restoring backups. The Hacker News reports no victim count or attacker identity and notes that zero-day status remains unverified.
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication The Hacker News
- Vulnerabilities in Mikrotik RouterOS software CERT Polska
- Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” Security Affairs
- Hackers Exploiting MikroTik RouterOS Vulnerability in the Wild to Gain Complete Network Access CyberSecurityNews
- MikroTik RouterOS flaws put exposed routers at risk Cybernews
Reading Insights
0
0
2 min
vs 3 min read
74%
538 → 139 words
Want the full story? Read the original article
Read on The Hacker News