Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
-
Attackers are actively compromising MikroTik routers by targeting the devices' Secure Shell (SSH) remote-access service when it is exposed to the internet. According to an attack warning published by CERT Polska on September 5, the threat actors are able to gain full administrative control over the affected routers without requiring any authentication.
Successful exploitation attempts have been observed dating back to at least September 2. CERT Polska has not disclosed the total number of victims affected by this campaign, nor does the advisory currently specify a unique identifier for the underlying flaw. Instead, the warning highlights the danger of leaving the SSH interface reachable from the public internet, as this configuration effectively allows unauthorized parties to bypass login credentials entirely.
- Affected component: MikroTik RouterOS SSH service
- Attack vector: Internet-exposed SSH interface
- Impact: Full administrative control of the router
Organizations using MikroTik hardware should immediately restrict remote access to the SSH service, either by disabling it entirely or by limiting exposure via firewall rules to trusted IP addresses only. Administrators are also advised to audit device logs for any unauthorized configuration changes or unknown user accounts that may indicate prior compromise.
Source: The Hacker News
Is your organization currently running any MikroTik routers with SSH exposed to the internet, and if so, what immediate steps are you taking to lock down access?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login