By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Exploit MikroTik RouterOS Flaws
Hackers are actively exploiting a recently disclosed chain of two vulnerabilities within MikroTik RouterOS to gain unauthorized control over affected devices. The primary vector for these attacks involves routers that have their Secure Shell (SSH) services exposed directly to the internet. This exposure creates a critical entry point for malicious actors to compromise the network infrastructure. The vulnerabilities, identified as CVE-2023-32144 and CVE-2023-32145, were patched by MikroTik in RouterOS versions 6.49.10, 7.1.5, and 7.10.1. However, a significant number of MikroTik devices, particularly those running older, unpatched versions of the operating system, remain vulnerable. The exploitation of these flaws allows attackers to bypass authentication mechanisms and execute arbitrary commands on the compromised routers. This level of access enables them to perform a variety of malicious activities, including redirecting network traffic, injecting malware, or using the routers as part of a botnet for further distributed denial-of-service (DDoS) attacks. The specific nature of the vulnerabilities suggests that attackers can exploit them in sequence to achieve full system compromise. CVE-2023-32144 is described as an authentication bypass vulnerability, while CVE-2023-32145 is an arbitrary code execution flaw. When chained together, these vulnerabilities present a severe threat to the security and integrity of networks utilizing MikroTik hardware. MikroTik, a Latvian company founded in 1996, is a well-known manufacturer of wireless and routing products. Their devices are widely used by internet service providers (ISPs), small and medium-sized businesses (SMBs), and home users globally due to their robust feature set and competitive pricing. The widespread deployment of MikroTik routers means that the impact of these vulnerabilities could be substantial, affecting a large number of internet-connected devices. Security researchers have warned that unpatched devices are prime targets, and the ease with which these vulnerabilities can be exploited necessitates immediate action from users. The recommendation for users is to update their MikroTik RouterOS to the latest stable versions as soon as possible to mitigate the risk of compromise. For devices where immediate updates are not feasible, disabling SSH access from the internet or restricting it to trusted IP addresses can serve as a temporary mitigation. The ongoing exploitation highlights the persistent threat of supply chain attacks and the critical importance of timely security patching for network infrastructure devices. The exploitation of these vulnerabilities is part of a broader trend of attackers targeting network edge devices, which often serve as the first line of defense for internal networks. The ability to hijack routers provides attackers with significant control over internet traffic and the potential to disrupt services or launch further attacks. The disclosure of these vulnerabilities and their subsequent exploitation underscore the need for continuous monitoring and proactive security measures for all network devices, especially those with internet-facing services.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.