DEV Community

Cover image for MikroTik Patches Critical "MikroTrick" Exploit Chain Under Active Attack
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

MikroTik Patches Critical "MikroTrick" Exploit Chain Under Active Attack

Summary

MikroTik has patched six vulnerabilities, including the "MikroTrick" exploit chain, which allows unauthenticated attackers to gain full administrative control over RouterOS devices. CERT Polska confirmed active exploitation of these flaws. Attackers are creating unauthorized accounts and establishing persistent network tunnels.

Take Action:

If you use MikroTik routers, first make sure the device is isolated from the internet and reachable only from trusted networks. Block SSH, WebFig, and bandwidth-test access from outside. Then install the fixed RouterOS version (7.23.4, 7.24.2, or 6.49.21 and newer) from the official MikroTik download page, check whether the device is Flagged as compromised, and delete any accounts you didn't create, such as one named "ops".


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)