Zero Day Room
Live
Defence

MikroTik Routers Hijacked via Internet-Exposed SSH

Attackers are exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication, according to a

Attackers are exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without...

Attackers are hijacking MikroTik routers by exploiting their internet-exposed Secure Shell (SSH) services to gain full administrative control without any authentication. CERT Polska issued this attack warning on September 5, with successful compromises observed since at least September 2.

According to the warning, the exploitation targets a combination of two vulnerabilities, which researchers have nicknamed 'MikroTrick'. The exact flaws and how they chain together to grant administrative access were not detailed in the public disclosure. The Hacker News reviewed the warning on September 6 and found no information on the number of victims or the identity of the attackers.

Vendor Patches and Affected Versions

MikroTik has released security updates to address the vulnerabilities. CERT Polska states these fixes prevent the observed attacks and recommends immediate installation. The patches are followed by a crucial step: checking for unauthorized configuration changes that may have occurred during a compromise.

The vendor's security update lists the specific RouterOS releases that contain the necessary fixes. The following table compares the affected versions noted by CERT Polska against the patched releases, as verified by The Hacker News on September 6.

Affected RouterOS VersionPatched RouterOS Release
Versions prior to fixes7.25beta3
Versions prior to fixes7.24.5
Versions prior to fixes7.23.5

It is critical to use the official RouterOS downloads for updates. The 7.23.5 release also serves as a regression fix for an IPv6 DHCP problem introduced in version 7.23.4, while retaining the security update.

Interim Mitigations and Post-Update Checks

Until the update can be installed, CERT Polska recommends disabling exposed services or restricting their access to trusted management networks. This advice applies specifically to SSH, WWW/WWW-SSL, and the bandwidth-test service. The agency also advises against initiating Transport Layer Security (TLS) connections or using the RouterOS built-in SSH client from any unpatched device. These are temporary restrictions for a broader set of vulnerabilities and are not a substitute for applying the official patch.

After updating, administrators must perform thorough checks. MikroTik's 'Flagged' status system is a key indicator. RouterOS flags a device when startup checks detect a suspicious configuration, subsequently disabling those entries and restricting certain functions. Users should check system logs and run the command /system/device-mode/print to inspect this status.

Even without a warning flag, the configuration should be inspected for unknown user accounts, scripts, and other unrecognized changes. CERT Polska specifically points to 'unexpected highly privileged ops accounts' and account-creation logs containing entries like 'ssh:-2@' as signs warranting investigation.

Recovery Steps for Compromised Devices

If warnings, logs, or configuration checks suggest a router has been compromised, CERT Polska outlines a recovery process. The agency emphasizes that the 'Flagged' status should not be cleared before evidence is preserved and analysis is complete.

The first step is to isolate the router from the network and preserve its logs and configuration before performing any reset. CERT Polska provides a preservation guide in Polish explaining how to export and download these files. Following evidence preservation, the device should be restored to factory settings and rebuilt using a trusted, verified configuration. A full backup from the potentially compromised device should not be blindly restored. Finally, all passwords, cryptographic keys, and other secrets that were in use must be changed.

The timeline of fixes and attacks leaves some questions unanswered. MikroTik's 7.25beta3 release notes carry a September 2 changelog date, with the beta and other initial fixes announced on September 3. Comparing these dates with CERT's attack timeline does not establish whether a fix was publicly available before the attacks began, leaving the zero-day status of the vulnerabilities unverified. The Hacker News has contacted both CERT Polska and MikroTik for further comment.

CERT Polska's warning clarifies that, according to MikroTik's documentation, home devices with their default firewall rules intact should block public access to management ports. This exploitation highlights the risk when those default configurations are altered or services are improperly exposed to the internet.

Related coverage

More from Defence