MikroTik SSH hijacks need no password, CERT Polska warns

CERT Polska warns that MikroTik routers with SSH exposed to the internet are being hijacked without any authentication.

CSBadmin
2 Min Read

CERT Polska is tracking a wave of router hijacks that needs no credentials, with MikroTik devices that leave SSH exposed to the internet taken over outright. Its September 5 advisory dates successful intrusions to at least September 2 and says victims lose full administrative control. The two-flaw chain behind the attacks has been nicknamed MikroTrick, though CERT has not detailed how the combination works.

Fixed builds are already available. RouterOS 6.49.21, 7.23.4, and 7.24.2 close the affected ranges, with 7.23.5 recommended on the long-term channel to fold in a separate IPv6 DHCP regression fix. A development-channel patch arrived in 7.25beta3.

CERT urges administrators to update immediately, then audit the device for unauthorized changes. Signs worth investigating include unexpected highly privileged operator accounts and account-creation log entries containing ssh:-2@. RouterOS may also flag a device when startup checks detect suspicious configuration, disabling the offending entries and restricting functions.

While the fix is pending, CERT’s interim guidance is to switch off exposed management services or confine them to trusted management networks, singling out SSH, web access, and the bandwidth-test feature. Owners of unpatched routers should also avoid initiating TLS connections and steer clear of the device’s built-in SSH client, which carry exposure risk while the flaws remain open.

For routers believed compromised, the guidance is blunt: isolate the unit, preserve logs and configuration for analysis, restore factory settings, and rebuild from a trusted configuration rather than restoring a backup from the possibly infected device. All passwords, keys, and secrets should be rotated afterward.

The takeaway for network teams is that default firewall rules on home MikroTik gear normally keep management ports off the public internet, so exposure is a configuration choice. Any device with SSH reachable from outside should be treated as at risk until patched and verified clean.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.