MikroTik patches flaws currently being exploited to take over routers
Summary
MikroTik has released patches for six vulnerabilities in its RouterOS firmware, two of which, when chained together (dubbed MikroTrick), allow attackers to gain full control of routers without authentication via SSH. This exploit chain is already being actively used in the wild against devices with publicly accessible SSH services, impacting over 122,500 MikroTik devices worldwide.
IFF Assessment
The discovery and active exploitation of vulnerabilities allowing unauthenticated remote takeover of networking devices poses a significant threat to defenders.
Severity
The exploit chain allows for unauthenticated remote takeover of devices, with a high attack vector and significant impact on confidentiality, integrity, and availability, warranting a critical CVSS score.
Defender Context
This article highlights a critical threat to network infrastructure, as attackers are actively exploiting vulnerabilities in MikroTik routers to gain complete control. Defenders should prioritize patching affected RouterOS versions and review their network configurations, particularly any exposed SSH services, to prevent compromise.