Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Summary

Attackers are actively exploiting internet-exposed MikroTik routers by hijacking their SSH service. This allows them to gain full administrative control without needing any authentication. The attacks have been ongoing since at least September 2, according to a CERT Polska warning.

IFF Assessment

FOE

The article describes a new attack vector targeting network devices, which poses a significant threat to defenders and network security.

Severity

9.8 Critical (AI Estimated)

This vulnerability allows for network-based authentication bypass, leading to full administrative control. The high CVSS score reflects the critical impact on Confidentiality, Integrity, and Availability, and the ease of exploitation due to the lack of authentication required for internet-facing services.

Defender Context

Defenders should immediately audit their MikroTik router configurations to ensure SSH is not exposed to the internet or is properly secured with strong authentication. This highlights the ongoing risk of misconfigured network devices being exploited by attackers to gain initial access or pivot within networks.

Read Full Story →