Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

The Hacker News by The Hacker News
September 6, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalSep 06, 2026Vulnerability / Network Security

Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska’s attack warning, published on September 5.

Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or attacker identity.

MikroTik’s security update lists fixed RouterOS releases. CERT says the fixes prevent the observed attacks and recommends immediate installation, followed by a check for unauthorized configuration changes.

According to the vendor’s default firewall explanation, home MikroTik devices block public access to management ports while their default firewall rules remain intact.

The Hacker News checked CERT’s affected RouterOS versions against MikroTik’s listed fixes on September 6. Use the official RouterOS downloads for your update.

Affected range reported by CERT Initial security fix Update guidance
From 6.0.0 below 6.49.21 6.49.21 RouterOS 6 security release
From 7.0.0 below 7.23.4 7.23.4 Use 7.23.5 on the long-term channel
From 7.24 below 7.24.2 7.24.2 Stable channel security release
No development range listed in CERT’s disclosure 7.25beta3 Development channel fix

The 7.23.5 regression fix addresses an IPv6 DHCP (Dynamic Host Configuration Protocol) problem introduced in 7.23.4 while retaining the security update.

Until the update can be installed, CERT recommends turning off exposed services or restricting access to trusted management networks, particularly for SSH, WWW/WWW-SSL, and bandwidth-test.

It also advises against initiating Transport Layer Security (TLS) connections or using RouterOS’s built-in SSH clients from an unpatched device. These temporary restrictions cover the broader set of vulnerabilities and do not replace the update.

MikroTik’s Flagged status guidance states that RouterOS flags a device when startup checks detect suspicious configuration. RouterOS disables those entries and restricts certain functions.

After updating, check the logs and run /system/device-mode/print to inspect that status. Even without a warning, inspect the configuration for unknown users, scripts, and other unrecognized changes.

CERT also points to unexpected highly privileged ops accounts and account-creation logs containing ssh:-2@ as signs to investigate.

If the warning, logs, or configuration suggest compromise, CERT recommends these recovery steps. Do not clear Flagged before preserving the evidence and completing the analysis.

  1. Isolate the router from the network and preserve its logs and configuration before resetting it. CERT’s preservation guide in Polish explains how to export and download the files.
  2. Restore factory settings and rebuild using a trusted, verified configuration. Do not blindly restore a full backup from the potentially compromised device.
  3. Change passwords, keys and other secrets in use.

CERT calls the reported 2-flaw combination MikroTrick. The Hacker News compared CERT’s warning and vulnerability disclosure on September 6. Neither explicitly identifies which 2 vulnerabilities form the observed chain or explains how they combine to give administrative control.

The 7.25beta3 release notes have a September 2 changelog date, while the beta and other initial fixes were announced on September 3. The Hacker News compared these release announcements with CERT’s attack timeline on September 6. Those dates do not establish whether a fix was publicly available before the attacks, so zero-day status remains unverified.

The Hacker News has contacted CERT Polska and MikroTik for comment.



Source link

The Hacker News

The Hacker News

Next Post

Why China Is the Bogeyman Data Center Enthusiasts Just Can't Quit

Recommended.

Gov.uk One Login loses certification for digital identity trust framework | Computer Weekly

Gov.uk One Login loses certification for digital identity trust framework | Computer Weekly

May 13, 2025
Rockford Fosgate Welcomes Josh Berry as Regional Sales Manager, OEM Marine

Rockford Fosgate Welcomes Josh Berry as Regional Sales Manager, OEM Marine

July 18, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
Sohu.com to Report Second Quarter 2026 Financial Results on August 10, 2026

Sohu.com to Report Second Quarter 2026 Financial Results on August 10, 2026

July 31, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio