DEV Community

kozhevniko
kozhevniko

Posted on

MikroTrick: How Two RouterOS Flaws Let Attackers Take Over MikroTik Routers Without a Password

MikroTrick: How Two RouterOS Flaws Let Attackers Take Over MikroTik Routers Without a Password

On September 5, 2026, CERT Polska disclosed six vulnerabilities in MikroTik RouterOS, two of them critical, and confirmed that attackers were already using them to take over devices whose SSH service is reachable from the internet. The combined exploit chain is tracked as MikroTrick. CISA added the two CVEs to its Known Exploited Vulnerabilities catalog on September 10, with a federal deadline of September 13.

The interesting part is not that a router can be compromised. It is that the attack needs neither a password nor a private key.

The two flaws

MikroTrick chains CVE-2026-67276 and CVE-2026-86060.

CVE-2026-67276 is a missing authentication weakness for a critical function (CWE-306). Public analysis describes it as a flaw in the SSH public-key verification path: when RouterOS compares an RSA public key, the exponent portion is not checked, so an attacker who knows the username and the public key modulus can forge a key and log in.

CVE-2026-86060 is improper neutralization of argument delimiters (CWE-88). After bypassing authentication, the attacker supplies a crafted username that injects additional arguments into the SSH login path, which escalates the session to full administrator privileges.

Neither flaw alone gives complete control. Together they allow an unauthenticated attacker who can reach SSH to obtain administrator access on the device.

Attribute Value
Chain name MikroTrick
CVE 1 CVE-2026-67276, missing authentication (CWE-306)
CVE 2 CVE-2026-86060, argument delimiter injection (CWE-88)
Reported CVSS 9.2 for each flaw in several trackers
Authentication required None
Attack surface SSH management service exposed to the internet
Source CERT Polska, September 5, 2026

Timeline and scale

CERT Polska recorded attacker activity starting September 2, 2026, one day before MikroTik released fixes on September 3. This makes it a zero-day exploitation event. MikroTik shipped RouterOS 6.49.21, 7.23.4, 7.24.2, and 7.25beta3, followed by 7.23.5 on September 4, and pushed an alert through its official app for the first time.

Public reporting cites more than 122,000 affected devices. That figure describes exposed and potentially vulnerable RouterOS instances rather than confirmed compromises, and the two should not be conflated.

What attackers leave behind

Reported indicators of compromise include SSH login attempts using the invalid username -2, the creation of an unauthorized high-privilege account named ops, and attacker source addresses including 82.192.72.4 (Leaseweb) and 103.102.31.18.

MikroTik added a Flagged mechanism to patched RouterOS builds. On boot, the device runs a self-check for known tampering artifacts and marks itself if it finds any. A flagged device should be treated as compromised.

Why this class of device matters

RouterOS runs on edge routers and wireless access points in small and medium businesses, ISPs, and home offices. These devices stay online continuously, connect the whole internal network, and often go unpatched for years. A router that is fully controlled can have its traffic sniffed, its routing and firewall rules rewritten, and its hardware turned into a proxy or tunnel.

The public-key bypass is the detail worth remembering. It defeats the assumption that SSH key authentication is inherently safer than a password. When the verification logic skips part of the key, the trust model collapses without any credential theft.

Remediation

  • Upgrade RouterOS to 6.49.21, 7.23.4, 7.24.2, or later. Patched versions block the observed attacks and add the Flagged self-check.
  • Restrict SSH, WebFig, and the bandwidth-test service to a trusted management network. Do not expose them to the internet.
  • Check logs for SSH logins using the username -2, and audit local users for unauthorized accounts such as ops.
  • Check whether the device reports itself as Flagged.
  • If a device shows signs of compromise, treat it as fully compromised. Changing the password is not enough once an attacker has held administrator access. Isolate the device, review configuration changes, and rebuild before returning it to service.

References

  • CERT Polska advisory on critical MikroTik RouterOS vulnerabilities under active exploitation, September 5, 2026.
  • CISA Known Exploited Vulnerabilities Catalog entries for CVE-2026-67276 and CVE-2026-86060.
  • MikroTik RouterOS release notes for 6.49.21, 7.23.4, 7.24.2, and 7.25beta3.
  • The Hacker News coverage of the MikroTrick chain and detection indicators.
  • Security Affairs analysis of the SSH authentication bypass and privilege escalation mechanics.

Top comments (0)