CyberSecurity SEE

MikroTik Releases Security Patches for Routers in Response to Zero-Day Attacks

MikroTik Releases Security Patches for Routers in Response to Zero-Day Attacks

Endpoint Security,
Governance & Risk Management,
Internet of Things Security

Chaining Two Flaws Leads to Full Compromise, Warn Polish Incident Responders

MikroTik Releases Security Patches for Routers in Response to Zero-Day Attacks
Image: MikroTik

Router manufacturer MikroTik has recently issued critical emergency patches after it was revealed that attackers have been actively exploiting multiple zero-day vulnerabilities associated with its products. This news has raised serious security concerns among users globally, prompting many to take immediate action to secure their networks.

The Polish Computer Emergency Response Team (CERT Polska) played a pivotal role in this situation by discovering six significant vulnerabilities within MikroTik RouterOS. This essential information was then communicated to MikroTik, leading to the swift release of security patches to address these issues.

According to CERT Polska, the implications of these vulnerabilities are severe. They indicated that an attacker could combine two of these flaws to gain complete control over a specific device, bypassing authentication entirely, particularly if the device supports remote access through the SSH protocol. This coordinated public disclosure of the attack chain, which has been dubbed “MikroTrick,” raises alarms as CERT Polska noted that malicious actors have been actively exploiting these vulnerabilities in recent days.

MikroTik, a Latvian company, is renowned for producing widely used routers and firewalls globally. As of Monday, the Internet of Things search engine Shodan identified approximately 3 million internet-connected MikroTik devices. A significant proportion of these devices is situated in China, followed by Brazil, Indonesia, the United States, Bangladesh, and India, indicating the widespread reach and potential vulnerability of MikroTik’s customer base.

The patches, which were released Thursday, cover several latest RouterOS versions—7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21—while all earlier versions remain at risk of exploitation. In a historical move to alert users and encourage updates, MikroTik sent out push notifications via the MikroTik app to users’ phones for the first time, as confirmed by CERT Polska.

In a security advisory issued the same day, MikroTik assured users that “most configurations are not at risk, but upgrading is highly recommended” for both business and home users. It also highlighted the importance of ensuring that SSH access is restricted from untrusted networks. MikroTik noted that the device’s default settings typically block external internet access to SSH, but users who have altered these settings should ensure that only trusted IP addresses can connect. Additionally, the company advised utilizing a robust VPN like WireGuard to manage router access, emphasizing the importance of not exposing any management ports publicly.

The Shadowserver Foundation, a nonprofit cybersecurity organization, subsequently reported that they had identified at least 122,500 MikroTik routers that were internet-connected and permitted remote access via SSH. However, they were unable to ascertain which RouterOS version these devices operated on, leaving uncertainty regarding how many might still be vulnerable.

Signs of Compromise

In various scenarios, affected routers may notify administrators about potential compromises. MikroTik’s RouterOS is designed to monitor the configuration at startup, conducting checks to identify any unauthorized access signs. If the system detects suspicious activity, it disables certain functionalities, sets a flagged parameter to “yes,” and logs this information within the device’s records.

Should a device be flagged, MikroTik strongly recommends that administrators assume a compromise has occurred. A complete audit of settings should be conducted before any reactivation of the system. This audit process includes changing all system passwords and updating to the latest RouterOS version to ensure maximum security.

Both CERT Polska and MikroTik have urged a manual audit of any device that was operating on a vulnerable RouterOS version, as there are limitations to the router’s ability to detect every type of exploit. CERT Polska warned that the routers might not recognize all the attacks targeting the six vulnerabilities it had reported earlier.

Administrative entities are strongly advised to update their devices without delay, subsequently reviewing configurations for any unauthorized users, scripts, scheduled tasks, proxy servers, and tunnels, as the risks associated with these vulnerabilities can have far-reaching implications.

The two vulnerabilities that underpin the MikroTrick attack chain have been assigned a critical CVSS rating of 9.2, indicating their potential to facilitate remote execution of malicious code on targeted devices, leading to complete control for attackers. The intricacies of the exploitation begin with CVE-2026-67276, which involves SSH user impersonation—highlighting a significant flaw in the authentication process. An attacker aware of an authorized RSA modulus could forge a legitimate signature and create an SSH command channel, leading to increased server vulnerabilities.

Upon establishing an authenticated SSH connection, the attacker could leverage the second vulnerability, CVE-2026-86060, associated with a flaw in RouterOS concerning argument handling in the SSH login pathway. This flaw enables modification of the trusted RouterOS policy mask, facilitating privilege escalation. These vulnerabilities underscore the urgent need for special attention to security measures by all MikroTik users to mitigate the risk of exploitation effectively.

Source link

Exit mobile version