Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

MikroTik Router Security Vulnerability: A Threat to Internet-Exposed SSH Without Authentication


MikroTik Router Security Vulnerability: A Threat to Internet-Exposed SSH Without Authentication. A recent discovery by CERT Polska reveals a critical vulnerability in MikroTik routers that can be exploited to gain administrative control over the devices without authentication, putting the security of internet-exposed SSH services at risk.

  • MikroTik routers are vulnerable to exploitation of the Secure Shell (SSH) remote-access service due to a critical vulnerability.
  • The vulnerability allows attackers to gain full administrative control over MikroTik routers without authentication.
  • The vulnerability affects RouterOS versions 6.0.0 and below 6.49.21, as well as certain security releases.
  • MikroTik has released security updates to fix the vulnerability, and recommends immediate installation.
  • Home users can block public access to management ports to prevent exploitation.
  • Temporary restrictions can be implemented to cover broader vulnerabilities until the update can be installed.
  • Recovery steps include isolating the router, preserving logs and configuration, and rebuilding with a trusted configuration.
  • The vulnerability highlights the importance of keeping software up to date and implementing robust security measures.



  • The cybersecurity landscape has been abuzz with the recent revelation of a critical vulnerability in MikroTik routers, specifically related to the exploitation of the Secure Shell (SSH) remote-access service. This vulnerability, discovered by CERT Polska, has been identified as a potential threat to the security of internet-exposed SSH services, which are accessible from the internet without authentication.

    According to the CERT Polska's attack warning, published on September 5, 2026, attackers have been exploiting this vulnerability to gain full administrative control over MikroTik routers without any authentication. This vulnerability affects at least September 2, 2026, with the Hacker News review of the warning finding no victim count or attacker identity.

    MikroTik's security update lists fixed RouterOS releases, which prevent the observed attacks and recommend immediate installation, followed by a check for unauthorized configuration changes. The vendor's default firewall explanation states that home MikroTik devices block public access to management ports while their default firewall rules remain intact.

    The affected range reported by CERT includes RouterOS versions 6.0.0 below 6.49.21, 6.49.21, RouterOS 6 security release from 7.0.0 below 7.23.4, 7.23.4, and use 7.23.5 on the long-term channel. Additionally, the stable channel security release is from 7.24 below 7.24.2, 7.24.2, and no development range listed in CERT's disclosure.

    The 7.23.5 regression fix addresses an IPv6 DHCP problem introduced in 7.23.4 while retaining the security update. Until the update can be installed, CERT recommends turning off exposed services or restricting access to trusted management networks, particularly for SSH, WWW/WWW-SSL, and bandwidth-test.

    It also advises against initiating Transport Layer Security (TLS) connections or using RouterOS's built-in SSH clients from an unpatched device. These temporary restrictions cover the broader set of vulnerabilities and do not replace the update.

    MikroTik's Flagged status guidance states that RouterOS flags a device when startup checks detect suspicious configuration. RouterOS disables those entries and restricts certain functions. After updating, check the logs and run /system/device-mode/print to inspect that status.

    Even without a warning, inspect the configuration for unknown users, scripts, and other unrecognized changes. CERT also points to unexpected highly privileged ops accounts and account-creation logs containing ssh:-2@ as signs to investigate.

    If the warning, logs, or configuration suggest compromise, CERT recommends these recovery steps. Do not clear Flagged before preserving the evidence and completing the analysis. Isolate the router from the network and preserve its logs and configuration before resetting it. Restore factory settings and rebuild using a trusted, verified configuration. Change passwords, keys, and other secrets in use.

    The reported 2-flaw combination is referred to as MikroTrick, and neither the CERT Polska's warning nor the vulnerability disclosure explicitly identifies which two vulnerabilities form the observed chain or explains how they combine to give administrative control.

    The 7.25beta3 release notes have a September 2 changelog date, while the beta and other initial fixes were announced on September 3. The Hacker News compared these release announcements with CERT's attack timeline on September 6, which do not establish whether a fix was publicly available before the attacks, so the zero-day status remains unverified.

    The Hacker News has contacted CERT Polska and MikroTik for comment. This vulnerability highlights the importance of keeping software up to date and implementing robust security measures to protect against such threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/MikroTik-Router-Security-Vulnerability-A-Threat-to-Internet-Exposed-SSH-Without-Authentication-ehn.shtml

  • https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html


  • Published: Sun Sep 6 05:32:01 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us