Summary
MikroTik has patched six vulnerabilities, including the "MikroTrick" exploit chain, which allows unauthenticated attackers to gain full administrative control over RouterOS devices. CERT Polska confirmed active exploitation of these flaws. Attackers are creating unauthorized accounts and establishing persistent network tunnels.
Take Action:
If you use MikroTik routers, first make sure the device is isolated from the internet and reachable only from trusted networks. Block SSH, WebFig, and bandwidth-test access from outside. Then install the fixed RouterOS version (7.23.4, 7.24.2, or 6.49.21 and newer) from the official MikroTik download page, check whether the device is Flagged as compromised, and delete any accounts you didn't create, such as one named "ops".
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)