Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Oleh Zai · Let's Make It Easy
Dipublikasikan 2026-09-06
The operational issue is not merely that a router has SSH; public exposure plus an unpatched RouterOS version creates a direct takeover path.
The operational issue is not merely that a router has SSH; public exposure plus an unpatched RouterOS version creates a direct takeover path.
Apa yang dilaporkan
CERT Polska says two vulnerabilities can be combined to take full control of internet-exposed MikroTik RouterOS devices over SSH without authentication.
CERT says it observed attacks and that patches prevent the observed exploitation.
Detail penting
The reported fixed versions include 6.49.21, 7.23.4, and 7.24.2, with channel-specific update guidance.
Catatan dan batas
The sources do not provide a victim count or attacker identity in the reviewed report.