Lily
Anne

MikroTrick Turns Exposed RouterOS SSH Into Full Admin Takeover

Lily Anne

Sep 9, 2026

5 min read

MikroTrick Turns Exposed RouterOS SSH Into Full Admin Takeover

TL; DR

Attackers are exploiting a critical MikroTik RouterOS vulnerability chain called MikroTrick against routers with internet-exposed SSH.

  • MikroTrick can provide unauthenticated administrative access to affected routers.
  • MikroTik released fixes in RouterOS 6.49.21, 7.23.4, 7.24.2 and 7.25beta3.
  • Organizations should patch immediately and inspect affected routers for unauthorized changes.

A newly disclosed MikroTik RouterOS vulnerability chain can let attackers take complete control of routers without authentication.

CERT Polska calls the two-flaw chain MikroTrick. Researchers have confirmed active exploitation against RouterOS devices whose SSH service is accessible from public networks. Successful attacks have occurred since at least September 2, 2026.

A compromised router gives attackers control over a trusted network entry point. They could create persistent access, redirect traffic or weaken network segmentation. The router could also support further attacks against internal endpoints.

Strengthen Endpoint Threat Response with Hexnode

How does the MikroTik RouterOS vulnerability enable takeover?

CERT Polska identified six RouterOS vulnerabilities affecting several services and security mechanisms. These include the SSH server and client, bandwidth-test service, X.509 certificate handling and WebFig interface.

Three vulnerabilities received particular attention:

  • CVE-2026-67276 bypasses SSH public-key authentication under specific conditions. An attacker who knows an authorized username and RSA modulus could authenticate without the corresponding private key.
  • CVE-2026-86060 manipulates SSH session privileges through a crafted username. Successful exploitation creates a session with full RouterOS administrative privileges.
  • CVE-2026-67277 affects the bandwidth-test service. It can expose kernel memory or trigger a remote denial-of-service condition.

CERT Polska confirmed that attackers combine two vulnerabilities to achieve unauthenticated administrative control. However, public disclosures do not identify the exact pair or explain how attackers combine them. Organizations should therefore avoid limiting detection to any assumed exploit sequence.

Which RouterOS versions require an update?

MikroTik released fixes across its supported release channels:

RouterOS branch Initial fixed version
Version 6 6.49.21
Version 7 long-term 7.23.4
Version 7 stable 7.24.2
Version 7 development 7.25beta3

Important: Version 7 Long-Term users should deploy RouterOS 7.23.5 instead of 7.23.4. Version 7.23.5 retains the security update and fixes the IPv6 DHCP regression introduced in 7.23.4.

Administrators using the long-term channel should deploy 7.23.5. This release retains the security update and fixes an IPv6 DHCP regression introduced in 7.23.4.

MikroTik also recommends keeping SSH closed to untrusted networks. Administrators should use a trusted management network or a secure VPN instead of exposing management ports publicly.

cybersecurity-kit

Cybersecurity kit

Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.

Download the Resource Kit

How can organizations detect MikroTrick exploitation?

Patching prevents the observed attacks, but it cannot remove changes made before the update. Administrators must inspect every previously exposed router for compromise.

CERT Polska identified several warning signs:

  • A highly privileged user named ops
  • Unknown users, scripts or scheduler tasks
  • Unrecognized proxy servers or network tunnels
  • Log entries containing ssh:-2@
  • Unexpected changes to the RouterOS configuration
  • A positive flagged value under /system/device-mode/print

Updated RouterOS releases check startup configurations for selected signs of unauthorized changes. When RouterOS finds suspicious entries, it disables recognized entries and marks the device as Flagged.

However, a missing Flagged marker does not prove that the router is safe. The mechanism detects only selected traces.

If indicators suggest compromise, isolate the router and preserve its logs and configuration. Then reset it to factory settings and rebuild it from a trusted configuration. Rotate passwords, SSH keys and other secrets. Do not restore a complete backup from the compromised device.

How can Hexnode reduce the wider enterprise risk?

The MikroTrick attack targets RouterOS, which Hexnode does not manage directly. However, Hexnode can reduce follow-on risks across managed endpoints and administrator access.

Enterprise risk Hexnode capability Mitigation
Administrators access network interfaces from non-compliant devices Hexnode UEM compliance policies Evaluates requirements such as OS version, encryption, device integrity and prohibited applications.
Non-compliant devices access sensitive resources Compliance-driven conditional access Enables the connected identity provider to block access or require stronger authentication.
Attackers target endpoints through a compromised router Hexnode XDR incident visibility Helps analysts investigate suspicious endpoint activity and process relationships.
Malicious activity attempts lateral movement Isolate Device Disconnects the affected endpoint from other networks while retaining its Hexnode XDR console connection.
Malicious processes or files appear on endpoints Kill Process and Quarantine File Allows analysts to terminate malicious processes and contain identified files.

These capabilities complement RouterOS patching, configuration reviews and network monitoring. They do not replace direct inspection of the affected router.

FAQs

Internet-exposed SSH gives attackers direct access to the RouterOS management service targeted by the MikroTrick vulnerability chain. Organizations should restrict SSH to trusted management networks or require access through a secure VPN.

Yes. CERT Polska confirmed that attackers can chain two RouterOS vulnerabilities to obtain administrative control without authentication. Public disclosures have not identified the exact two vulnerabilities used together or documented the complete exploit sequence.

The initial fixed releases are RouterOS 6.49.21, 7.23.4 for long-term, 7.24.2 for stable and 7.25beta3 for development. Administrators on the long-term channel should use 7.23.5 because it retains the security fixes while addressing an IPv6 DHCP regression in 7.23.4

Patch exposed RouterOS devices immediately

MikroTrick shows how one exposed management service can turn a router into an attacker-controlled foothold. Organizations should patch the MikroTik RouterOS vulnerability, restrict SSH access and investigate every previously exposed device.

Edge-device security must connect with endpoint compliance, identity controls and threat monitoring. That combined approach helps contain follow-on activity before a router compromise spreads further.

Share

Lily Anne

Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.