Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
A critical vulnerability in MikroTik routers allows attackers to bypass SSH authentication, and exploitation is already underway. Due to the ease of exploitation, assume that many devices are already compromised, and immediately apply the latest patch to prevent further damage.
Mikrotik has released a patch to address a significant vulnerability in its router firmware. This vulnerability, discovered and reported by the SANS Internet Storm Center, enables attackers to bypass SSH authentication, providing them with unauthorized access to affected devices. The vulnerability is currently being actively exploited, and security researchers strongly advise assuming that many MikroTik routers are already compromised. The patch is designed to detect compromised devices and set their status to ‘Flagged’ to indicate that they have been targeted. The SANS Internet Storm Center urges users to immediately update their MikroTik routers to the latest firmware version to mitigate the risk of further exploitation. The vulnerability allows attackers to add new accounts to devices, maintaining access even after a patch is installed, highlighting the urgency of applying the fix. This represents a serious threat to organizations relying on MikroTik routers, particularly those in critical infrastructure sectors.