Code Defence Cyber security

CERT Polska warns of active MikroTik RouterOS SSH takeover campaign exploiting unauthenticated flaw

National computer emergency response teams have issued emergency security advisories warning of active wild exploitation targeting internet-exposed edge routing hardware. Threat actors leverage unverified authentication bypass mechanisms to obtain full administrative control over network gateways without valid user credentials.

The attack campaign targets MikroTik RouterOS devices configured with public-facing SSH management services. Threat actors exploit vulnerabilities in SSH remote access subroutines to obtain administrator access, subsequently injecting persistent rogue account entries formatted as ssh:-2@ and modifying system device-mode parameters. CERT Polska confirmed that successful compromises allow adversaries to route malicious transit traffic, rewrite firewall rules, and establish persistent access channels across corporate edge boundaries.

Subverting edge routing appliances destroys perimeter network isolation. Because MikroTik gateways govern local network routing, VPN termination tunnels, and firewall access control lists, an unauthenticated host takeover permits threat actors to capture internal transit traffic, disable security logging, and pivot directly into internal corporate subnets.

– Apply emergency RouterOS maintenance software updates published by MikroTik across all edge routing hardware immediately.

– Restrict public internet access to RouterOS SSH, WWW, and bandwidth-test management interfaces using strict access lists.

– Inspect system device logs and configuration registries for unauthorized user creations or Flagged device-mode warnings.

– Perform a complete factory system reset and configuration rebuild from trusted backups if compromised accounts are identified.

Perimeter network protection demands strict management plane isolation and immediate firmware maintenance updates to ensure edge gateways remain completely protected from unauthenticated remote administrative takeover. #CodeDefence #MikroTik #RouterOS #EdgeSecurity #NetworkSecurity #AuthBypass #PatchManagement #AppSec
/

Scroll to Top