MikroTik Routers Under Active Exploitation via SSH Flaw
On September 5, CERT Polska issued a warning about attackers exploiting MikroTik routers with exposed SSH services to gain full administrative control without authentication. The campaign, dubbed MikroTrick, has been active since at least September 2, though the exact number of victims and attacker identities remain unknown.
The vulnerability affects multiple RouterOS versions, with fixes released in the following updates:
- 6.x: 6.49.21 (for versions below 6.49.21)
- 7.x: 7.23.4 (for versions below 7.23.4) and 7.24.2 (for versions below 7.24.2)
- Development: 7.25beta3 (for unlisted versions)
A regression fix (7.23.5) was later issued to address an IPv6 DHCP issue introduced in 7.23.4 while maintaining security patches. CERT recommends immediate updates and advises temporarily disabling exposed services (SSH, WWW/WWW-SSL, bandwidth-test) or restricting access to trusted networks until patches are applied.
MikroTik’s default firewall blocks public access to management ports on home devices, but compromised configurations may still be at risk. Post-update, administrators should check logs for unauthorized changes, including unexpected privileged accounts (e.g., ssh:-2@) or suspicious scripts.
If compromise is detected, CERT advises isolating the router, preserving logs, and performing a factory reset avoiding full backups from the compromised device. Passwords, keys, and other secrets should be rotated as part of recovery.
The exact vulnerabilities chained in the attack remain undisclosed, and it is unclear whether the flaws were zero-days before fixes were released. MikroTik and CERT Polska have not yet provided further details.
Source: https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
MikroTik cybersecurity rating report: https://www.rankiteo.com/company/mikrotik
"id": "MIK1788690225",
"linkid": "mikrotik",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Networking Hardware',
'name': 'MikroTik',
'type': 'Technology Vendor'}],
'attack_vector': 'Exposed SSH services',
'customer_advisories': 'Update RouterOS, disable exposed services, monitor '
'logs, and perform factory resets if compromised.',
'date_detected': '2023-09-02',
'date_publicly_disclosed': '2023-09-05',
'description': 'CERT Polska issued a warning about attackers exploiting '
'MikroTik routers with exposed SSH services to gain full '
'administrative control without authentication. The campaign, '
'dubbed *MikroTrick*, has been active since at least September '
'2. The vulnerability affects multiple RouterOS versions, and '
'fixes were released in updates 6.49.21, 7.23.4, 7.24.2, and '
'7.25beta3. A regression fix (7.23.5) was later issued to '
'address an IPv6 DHCP issue. CERT recommends immediate updates '
'and advises temporarily disabling exposed services or '
'restricting access to trusted networks until patches are '
'applied.',
'impact': {'operational_impact': 'Full administrative control of routers',
'systems_affected': 'MikroTik routers with exposed SSH services'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'corrective_actions': 'Patch management, '
'restricting access to '
'management ports, log '
'monitoring, and factory '
'resets for compromised '
'devices',
'root_causes': 'Exposed SSH services with '
'authentication bypass '
'vulnerability'},
'recommendations': 'Immediately update RouterOS, disable exposed services or '
'restrict access to trusted networks, monitor logs for '
'unauthorized changes, and perform factory resets if '
'compromise is detected.',
'references': [{'date_accessed': '2023-09-05', 'source': 'CERT Polska'}],
'response': {'containment_measures': 'Disable exposed services (SSH, '
'WWW/WWW-SSL, bandwidth-test) or '
'restrict access to trusted networks',
'enhanced_monitoring': 'Check logs for unauthorized changes '
'(e.g., unexpected privileged accounts '
'like `ssh:-2@` or suspicious scripts)',
'recovery_measures': 'Isolate router, preserve logs, perform '
'factory reset (avoiding full backups from '
'compromised device), rotate '
'passwords/keys/secrets',
'remediation_measures': 'Apply RouterOS updates (6.49.21, '
'7.23.4, 7.24.2, 7.25beta3, or 7.23.5 '
'for regression fix)'},
'title': 'MikroTik Routers Under Active Exploitation via SSH Flaw',
'type': 'Unauthorized Access',
'vulnerability_exploited': 'SSH authentication bypass (exact vulnerability '
'undisclosed)'}