MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Summary

Two chained vulnerabilities in MikroTik RouterOS, dubbed MikroTrick, allow attackers to gain full administrative control of internet-exposed routers. This exploit bypasses the need for passwords or SSH keys by chaining an SSH state-machine flaw with an argument-injection bug in the login process.

IFF Assessment

FOE

The chaining of vulnerabilities allows for unauthenticated remote code execution and administrative takeover of MikroTik routers, posing a significant threat to network infrastructure.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 13, 2026. Known ransomware use: Unknown.

Defender Context

This chained exploit targeting MikroTik routers highlights the critical importance of patching network devices promptly, especially those exposed to the internet. Defenders should prioritize identifying and securing all MikroTik devices, and implement network segmentation to limit the blast radius of potential compromises.

Read Full Story →