← BACK TO FEED
MikroTikRouterOSSSH vulnerabilitynetwork securityCERT Polska

MikroTik Routers Being Hijacked Over SSH With Zero Authentication Required

Attackers have been exploiting internet-exposed SSH services on MikroTik routers since at least September 2, gaining full administrative control without authentication through a two-vulnerability chain dubbed "MikroTrick" by CERT Polska. Affected devices run RouterOS versions across the 6.x, 7.x, and development channels, with fixes available in releases 6.49.21, 7.23.4/7.23.5, 7.24.2, and 7.25beta3. Users are urged to install updates immediately, check for signs of compromise such as unknown accounts or suspicious logs, and temporarily restrict access to exposed services until patching is complete.

Attackers are taking full administrative control of MikroTik routers by exploiting internet-exposed SSH services that require no authentication whatsoever. CERT Polska published an attack warning on September 5, with confirmed incidents dating back to at least September 2.

No victim count has been disclosed, and nobody's publicly naming the attackers yet.

MikroTik has released patched versions of RouterOS across its supported branches. CERT says the fixes stop the observed attacks cold, and recommends installing them immediately, then auditing your configuration for anything that shouldn't be there.

The affected version ranges and their corresponding fixes break down like this: RouterOS 6.x users running anything from 6.0.0 up to 6.49.21 need to move to 6.49.21. On the 7.x stable branch, anything from 7.0.0 below 7.23.4 is vulnerable, with 7.23.5 recommended since it includes both the security fix and a regression patch for an IPv6 DHCP issue introduced in 7.23.4. Users on 7.24.x below 7.24.2 should update to 7.24.2. A development channel fix also landed in 7.25beta3, with a changelog date of September 2 and an announcement on September 3.

Whether patches were publicly available before the attacks began is still unclear, so zero-day status hasn't been confirmed or ruled out.

If you can't patch immediately, CERT recommends disabling any internet-exposed management services or locking them down to trusted networks only. SSH, WWW, WWW-SSL, and bandwidth-test are specifically called out. You should also avoid initiating TLS connections or using RouterOS's built-in SSH client from any unpatched device. These are temporary mitigations, not substitutes for the actual update.

On the question of scope: MikroTik's default firewall blocks public access to management ports on home devices, provided those default rules haven't been touched. If you've customised your firewall, that assumption doesn't hold.

CERT is calling the two-vulnerability combination behind these attacks "MikroTrick." Which two flaws form the chain, and exactly how they interact to hand over admin access, hasn't been spelled out in any public disclosure yet.

For checking whether a device is already compromised, RouterOS flags suspicious configurations detected at startup, disabling affected entries and restricting certain functions. After patching, run /system/device-mode/print and check the logs. Even if no flag appears, go through the configuration manually. CERT flags unexpected highly privileged accounts named "ops" and SSH login entries containing ssh:-2@ as specific indicators worth investigating.

If something looks off, don't just reset and move on. Isolate the router first, preserve the logs and configuration, then perform a factory reset and rebuild from a known-good configuration. Restoring a full backup from a potentially compromised device is explicitly not recommended. Change all passwords and keys regardless.

The Hacker News has reached out to both CERT Polska and MikroTik for comment.

READ NEXT
Fire Ant Goes Deeper: China-Linked Hackers Hit Cisco Routers, TACACS Servers and Linux HostsThree Hacker Groups Are Quietly Carving Up Russian Enterprise NetworksGoogle Quietly Patches Exploited Pixel Modem Flaw — No Click Required