news.mlab.sh
Back to the feed
threat-intel

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

High
Summary

Attackers are exploiting unsecured MikroTik routers with exposed SSH services to gain administrative control. CERT Polska issued a warning about this issue, and MikroTik has released security updates to address the vulnerability. Affected devices should be updated immediately, and users are advised to restrict access to management ports and investigate suspicious activity.

CERT Polska issued an attack warning on September 5 regarding MikroTik routers being exploited through internet-accessible SSH services. Successful attacks began at least on September 2. MikroTik’s security updates address the issue, and CERT Polska recommends immediate installation of these updates to prevent exploitation. The vulnerability stems from routers being accessible from the internet without authentication, allowing attackers to gain full administrative control. MikroTik’s default firewall configuration blocks public access to management ports, but this doesn’t prevent attacks if SSH is exposed. CERT Polska advises disabling exposed services and restricting access to trusted management networks, particularly SSH, WWW/WWW-SSL, and bandwidth-test. They also recommend avoiding TLS connections and RouterOS’s built-in SSH clients from unpatched devices. MikroTik flags a device when startup checks detect suspicious configuration and disables certain functions. CERT Polska recommends preserving logs and configuration before isolating the router and restoring factory settings using a trusted configuration, avoiding blind backups. Users should also change passwords, keys, and other secrets and investigate suspicious activity, such as unexpected highly privileged ops accounts and account-creation logs containing ssh:-2@. The Hacker News compared CERT’s warning and vulnerability disclosure on September 6, finding neither explicitly identified the two vulnerabilities that combine to give administrative control, nor established whether a fix was publicly available before the attacks, leaving the zero-day status unverified.

Read the full article at The Hacker News