
Exposed MikroTik SSH Flaw Lets Attackers Seize Router Admin Control
CERT Polska warns that attackers are exploiting publicly reachable MikroTik SSH to gain full administrative control without authentication, with assaults dating back to Sept 2; MikroTik RouterOS updates exist across affected versions and should be installed immediately from official sources, followed by checking for unauthorized changes. The advisory notes a two-flaw chain dubbed MikroTrick and urges disabling exposed services or restricting SSH/WWW management to trusted networks until patched. Do not use TLS or the built-in SSH on unpatched devices, and monitor logs for signs of compromise (e.g., unknown users or ssh:-2@ entries). After updating, verify the device-mode status and examine logs; if compromised, isolate the router, preserve logs, reset to factory, and recreate configuration from a trusted source rather than restoring backups. The Hacker News reports no victim count or attacker identity and notes that zero-day status remains unverified.
