Security · 3 MIN READ

MikroTrick RouterOS Exploit Chain: Patch and Lock Down SSH

MikroTik has patched six RouterOS vulnerabilities after attackers began exploiting a two-flaw SSH chain known as MikroTrick. Organizations should update affected routers, remove public management exposure, inspect devices for compromise, and treat missing warning indicators cautiously.

MikroTrick RouterOS Exploit Chain: Patch and Lock Down SSH

MikroTik has released RouterOS updates for six vulnerabilities affecting components including SSH, WebFig, bandwidth testing, certificate handling, and the SSH client. Two of the flaws can be chained to take full control of routers whose SSH service is reachable from public networks, and CERT Polska has observed active attacks using the chain.


How the MikroTrick Chain Works

The first vulnerability, CVE-2026-67276, results from incomplete validation of RSA public keys during SSH authentication. An attacker who knows a username and the public modulus of that user's key can construct a private key that RouterOS accepts, gaining the privileges of the targeted account.

The second vulnerability, CVE-2026-86060, involves RouterOS handling of usernames beginning with special characters. Chaining it with the authentication flaw allows an attacker to escalate privileges and obtain full administrative control of the underlying system.

The broader set of six patched vulnerabilities affects several RouterOS components:

  • SSH server and client

  • WebFig management interface

  • Bandwidth-test service

  • X.509 certificate handling code


Internet-Exposed SSH Raises the Risk

Public SSH access is not enabled by default, but Shadowserver Foundation scans found more than 122,500 MikroTik devices with SSH reachable from the internet. The largest observed concentrations were in Brazil, the United States, and Indonesia.

MikroTik recommends against enabling SSH on the internet interface. If SSH access has been opened manually, access should be restricted to trusted IP addresses or replaced with VPN-based management using WireGuard, with no management ports directly exposed.


Fixed RouterOS Releases

MikroTik issued patches in the following RouterOS releases:

  • RouterOS 7.25 beta 3

  • RouterOS 7.24.2

  • RouterOS 7.23.4

  • RouterOS 6.49.21

Asset owners should inventory RouterOS devices, record their installed firmware releases, identify which management services are exposed, and prioritize internet-facing routers for immediate remediation.


Responding to Possible Compromise

RouterOS can mark a device as Flagged when its configuration shows signs of unauthorized changes. This status is written to the Log section, but it does not identify which vulnerability was exploited. CERT Polska also cautions that the absence of the marker does not prove that a router is safe.

If a router is marked Flagged:

  • Isolate it immediately.

  • Preserve its configuration and logs for investigation.

  • Reset it to factory defaults.

  • Reconfigure it from a known-clean file.

  • Rotate every key and password used on the device.

If updates cannot be installed immediately, block or disable SSH, WWW, WWW-SSL, and the bandwidth-test server on untrusted networks. These restrictions reduce exposure but should not replace installation of the corrected firmware.


How ConnectMyAssets Helps

ConnectMyAssets runs as a hardened on-prem OVA, keeping infrastructure data within the organization. In environments where MikroTik routers operate alongside supported multi-vendor network gear, its modules can strengthen the surrounding inventory, exposure-management, and remediation process:

  • Dynamic CMDB automatically discovers managed assets and uses LLDP data to map topology and dependencies.

  • CVE Tracking associates vulnerabilities with individual managed assets, helping teams prioritize exposed infrastructure.

  • Firewall Management supports cross-vendor policy review and helps uncover rules that unnecessarily expose management services.

  • SSH Bastion provides audited, browser-based SSH access for managed devices, reducing reliance on directly exposed administrative ports.

  • Backup & History maintains SHA256-verified configuration versions and supports one-click rollback on supported equipment.

  • Compliance Engine scores controls against frameworks including NIS2, ISO 27001, PCI-DSS, CISA, and NIST.

  • Automation & ZTP can distribute approved changes across supported infrastructure at scale.

These capabilities do not replace MikroTik's prescribed isolation, factory-reset, and clean-reconfiguration process for a compromised RouterOS device. They help teams maintain the accurate asset records, controlled administrative access, configuration history, and remediation oversight needed to respond consistently across the rest of the managed network.

Source: Network World

Share this articleLinkedIn ↗Email ↗

Keep exploring.

All articles
Security

Critical Check Point Management Flaw Allows Root Code Execution

A critical vulnerability in Check Point Security Management and Log Servers could let an unauthenticated network attacker execute code as root. Because the management server controls firewall policy and administrator access, organizations should apply the LivePatch fix and verify every potentially exposed system.

Read article
Security

Check Point Management-Server RCE: What to Track

CERT-FR has reported a vulnerability in Check Point products that can allow remote arbitrary code execution. Administrators should identify affected management assets, apply the required vendor updates, and search SmartConsole logs for the login-failure pattern highlighted in the advisory.

Read article
Security

Cisco ISE Zero-Day Under Active Attack

Cisco has disclosed a maximum-severity authentication-bypass vulnerability in ISE that is already being exploited. Network teams should identify affected systems, follow Cisco’s remediation guidance, and document patch or mitigation status across their network-access infrastructure.

Read article