Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2688+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
NEWS

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

CERT Polska warns of active attacks gaining full admin control of internet-facing MikroTik RouterOS devices via SSH with no authentication needed.

Dylan H.

News Desk

September 6, 2026
2 min read

Unauthenticated Takeover Over SSH

CERT Polska has issued a warning that attackers are actively exploiting internet-exposed SSH services on MikroTik RouterOS devices to gain full administrative control — without needing to authenticate at all. According to the September 5 advisory, successful attacks have been observed dating back to at least September 2, 2026.

CERT Polska is tracking the attack chain under the name "MikroTick," describing it as a combination of two flaws in RouterOS's SSH handling. The agency has not yet published the specific CVE identifiers or the full technical exploit chain, but has confirmed that the combination allows a remote, unauthenticated attacker to obtain administrator-level access to the router.


Affected Versions

RouterOS BranchVulnerable RangePatched Version
Long-term/legacy6.0.0 – 6.49.206.49.21
Stable (v7)7.0.0 – 7.23.37.23.5
Stable (v7, later)7.24 – 7.24.17.24.2

Any MikroTik device running RouterOS within these ranges with SSH reachable from the internet should be considered at risk until patched.


Why This Matters

MikroTik routers are widely deployed by ISPs, small businesses, and prosumers, and are frequently left with management interfaces — including SSH — exposed directly to the internet for remote administration. A pre-authentication path to full admin control on a router is a high-value target for attackers: routers sit at the network edge, see all traffic passing through them, and are a common building block for large-scale DDoS botnets, traffic-interception operations, and further network compromise.

MikroTik devices in particular have a long history of being recruited into botnets (including past campaigns tied to large-scale credential theft and DNS hijacking) precisely because so many units remain internet-facing and unpatched for extended periods.


Recommended Actions

  1. Patch immediately to RouterOS 6.49.21, 7.23.5, or 7.24.2 depending on your branch.
  2. Disable SSH access from the WAN interface — restrict management access to a trusted LAN, VPN, or bastion host.
  3. Audit user accounts on any internet-exposed device for unauthorized additions.
  4. Review device configuration for unexpected firewall rule changes, new scheduled scripts, or altered NAT/routing rules that could indicate persistence.
  5. Check logs for SSH connection attempts and successful logins from unfamiliar source IPs around or after September 2, 2026.

Sources

  • The Hacker News — Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
#MikroTik#RouterOS#SSH#CERT Polska#Router Security#Network Security

Related Articles

Authorities Disrupt APT28 Router DNS Hijacks Targeting

An international law enforcement operation has dismantled FrostArmada, an APT28 campaign that hijacked DNS on compromised MikroTik and TP-Link routers to...

4 min read

CERT-EU: European Commission Hack Exposes Data of 30 EU

CERT-EU has attributed the European Commission cloud account compromise to the TeamPCP threat group, revealing the breach exposed sensitive data from at...

4 min read

SSH Hardening Best Practices

Secure your SSH servers with essential hardening techniques including key-based authentication, fail2ban configuration, and advanced security measures.

6 min read
Back to all News