MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Summary
Two chained vulnerabilities in MikroTik RouterOS, dubbed MikroTrick, allow attackers to gain full administrative control of internet-exposed routers. This exploit bypasses the need for passwords or SSH keys by chaining an SSH state-machine flaw with an argument-injection bug in the login process.
IFF Assessment
The chaining of vulnerabilities allows for unauthenticated remote code execution and administrative takeover of MikroTik routers, posing a significant threat to network infrastructure.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 13, 2026. Known ransomware use: Unknown.
Defender Context
This chained exploit targeting MikroTik routers highlights the critical importance of patching network devices promptly, especially those exposed to the internet. Defenders should prioritize identifying and securing all MikroTik devices, and implement network segmentation to limit the blast radius of potential compromises.