← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Attackers Exploit MikroTik Routers via Internet-Exposed SSH for Unauthorized Access

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Attackers exploit MikroTik routers via exposed SSH services.
  • Vulnerability allows full administrative control without authentication.
  • MikroTik released RouterOS security updates to fix the issue.
  • CERT Polska recommends immediate updates and configuration checks.

MikroTik Routers Under Attack

CERT Polska issued a warning on September 5 regarding active exploitation of MikroTik routers. Attackers are targeting routers with Secure Shell (SSH) remote-access services exposed to the internet, enabling them to gain full administrative control without requiring authentication. Successful attacks have been observed since at least September 2.

Security Updates Released

MikroTik has released security updates for its RouterOS, listing fixed versions that prevent the observed attacks. CERT Polska strongly recommends immediate installation of these updates. Following the update, users should check their router configurations for any unauthorized changes that may have occurred.

Mitigation and Recovery Steps

Until updates can be installed, CERT Polska advises turning off exposed services like SSH, WWW/WWW-SSL, and bandwidth-test, or restricting access to trusted management networks. They also recommend against initiating TLS connections or using RouterOS's built-in SSH clients from unpatched devices. If compromise is suspected, CERT recommends isolating the router, preserving logs and configuration, restoring factory settings, and rebuilding with a verified configuration.

Checking for Compromise

MikroTik's RouterOS can flag devices when suspicious configurations are detected during startup, disabling affected entries and restricting functions. After updating, users should check logs and run '/system/device-mode/print' to inspect the device status. Signs of compromise include unknown users, scripts, unrecognized changes, unexpected highly privileged operations accounts, and account-creation logs containing 'ssh:-2@'.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~8 min · 6 stories · Sep 06

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Attackers are exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication, according to CERT Polska. MikroTik has released security updates for RouterOS to address these vulnerabilities, and users are advised to install them immediately.