Updated
Updated · The Hacker News · Sep 6
Attackers Seize MikroTik Routers via SSH, Hitting RouterOS 6.49.21 and 7.23.4 Users
Updated
Updated · The Hacker News · Sep 6

Attackers Seize MikroTik Routers via SSH, Hitting RouterOS 6.49.21 and 7.23.4 Users

3 articles · Updated · The Hacker News · Sep 6

Summary

  • CERT Polska said attackers have been exploiting internet-exposed MikroTik SSH since at least Sept. 2 to gain full administrative control without authentication.
  • MikroTik issued fixes for RouterOS versions below 6.49.21, 7.23.4 and 7.24.2, while long-term users are told to install 7.23.5 because it keeps the security patch and fixes a DHCP regression.
  • Until patching is complete, CERT urged admins to disable or restrict exposed management services—especially SSH, WWW/WWW-SSL and bandwidth-test—and avoid starting TLS or built-in SSH client sessions from unpatched devices.
  • Compromise checks include RouterOS Flagged status, unknown users or scripts, unusually privileged ops accounts and logs showing ssh:-2@; suspected devices should be isolated, preserved, factory-reset and rebuilt from trusted configurations.
  • CERT calls the two-flaw chain 'MikroTrick,' but neither it nor MikroTik has identified the exact vulnerabilities or confirmed whether the attacks were true zero-days.

Insights

What hidden dangers lie within the undisclosed MikroTrick vulnerability chain that gives hackers total control over enterprise routers?
Are traditional router backups actually restoring your network's security, or just quietly reinstalling a hacker's invisible backdoor?