Hackers exploit new MikroTik RouterOS flaws to hijack routers
-
Attackers are actively chaining two recently disclosed security flaws in MikroTik RouterOS to seize control of devices that have SSH services exposed online. The campaign targets routers that have not yet been updated with the vendor’s latest patches.
The exploitation chain combines a privilege escalation vulnerability with an authentication bypass issue. When used together, they allow an unauthenticated remote attacker to gain administrative access to the router. Once inside, the attackers can modify device settings, inject malicious configurations, or use the compromised router as a pivot point for further network intrusions.
The flaws affect RouterOS versions that predate the latest stable release. MikroTik has already addressed the issues in newer firmware builds, and administrators are strongly advised to apply those updates without delay. In addition to patching, it is recommended to restrict SSH access to trusted IP addresses only, and to disable the service entirely if it is not strictly required.
- Affected: MikroTik RouterOS versions prior to the latest patched release.
- Mitigation: Update to the latest RouterOS build, enforce firewall rules to limit SSH exposure, and audit device logs for unusual activity.
Routers are often overlooked in patch management routines, yet they remain a high-value target for attackers seeking persistent access to internal networks. Given that this exploitation is already underway, immediate action is warranted.
Source: BleepingComputer
Is your organisation currently exposing SSH on any MikroTik devices, and if so, how are you prioritising the rollout of these critical updates?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login