Code Defence Cyber security

CERT Polska details MikroTrick exploit chain allowing unauthenticated root takeover of MikroTik RouterOS devices

National computer emergency response teams have published technical breakdowns of an active edge router compromise chain. Adversaries chain an SSH state-machine vulnerability with a login argument injection bug to obtain root administrative access on edge gateways without passwords or SSH keys.

The attack chain, dubbed MikroTrick, combines SSH state-machine flaw CVE-2026-67279 and argument injection flaw CVE-2026-86060 affecting MikroTik RouterOS releases. Unauthenticated remote actors transmit malformed SSH parameter sequences during connection setup to bypass authentication handlers, injecting rogue system user entries formatted as ssh:-2@ and setting system device-mode status flags to Flagged. Technical reports confirm compromised routers are weaponized to redirect DNS queries, inspect transit traffic, and establish covert access tunnels into internal subnets.

Subverting edge routing hardware destroys network perimeter boundaries. Because MikroTik gateways manage edge traffic routing, local firewall rules, and VPN tunnel terminations, an unauthenticated takeover permits adversaries to capture unencrypted network transit data and pivot into adjacent enterprise subnets.

– Upgrade RouterOS software installations immediately to maintenance builds 6.49.21, 7.23.4, or 7.24.2 published by MikroTik.

– Restrict public internet routing to RouterOS SSH, WinBox, and web administration ports using strict firewall access control lists.

– Execute the /system/device-mode/print command to check whether router device-mode status has been altered to Flagged.

– Perform complete system resets and configuration rebuilds from verified clean backups if rogue account entries are detected.

Perimeter edge protection demands strict management interface isolation and immediate firmware update application to ensure enterprise gateways remain protected from unauthenticated remote access manipulation. #CodeDefence #MikroTik #RouterOS #MikroTrick #EdgeSecurity #NetworkSecurity #AuthBypass #AppSec
/

Scroll to Top