Interestana
Home/News/MikroTik Routers Vulnerable to Unauthenticated Remote Takeover
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

MikroTik Routers Vulnerable to Unauthenticated Remote Takeover

MikroTik Routers Vulnerable to Unauthenticated Remote Takeover

A sophisticated attack chain, identified by CERT Polska and named MikroTrick, has been discovered that enables attackers to achieve complete administrative control over MikroTik routers. This exploit bypasses standard security measures, including passwords and SSH keys, and does not require any form of authentication to succeed. The attack targets Internet-exposed MikroTik routers, posing a significant risk to network infrastructure that relies on these devices for connectivity and security.

The MikroTrick chain is comprised of two distinct vulnerabilities. The first is an SSH state-machine flaw, cataloged as CVE-2026-67279. This vulnerability exploits how the SSH service handles its internal state, potentially allowing an attacker to manipulate the connection in a way that bypasses authentication checks. The second vulnerability is an argument-injection bug within the RouterOS login process, assigned the identifier CVE-2026-86060. This flaw allows an attacker to inject malicious arguments into commands or processes during the login attempt, which can be leveraged to gain unauthorized access or escalate privileges. By chaining these two vulnerabilities together, attackers can effectively circumvent the need for valid credentials.

Attack logs indicate that malicious activity exploiting this vulnerability chain has been observed as early as the current year. The implications of such a widespread vulnerability are substantial, as MikroTik routers are commonly used by Internet service providers (ISPs), businesses, and home users globally. A successful exploitation could lead to a range of malicious activities, including the redirection of network traffic, the injection of malware, the disruption of internet services, or the use of compromised routers as part of a botnet for further attacks. The lack of authentication required makes these devices particularly attractive targets for automated scanning and exploitation campaigns.

CERT Polska's analysis highlights the critical nature of these vulnerabilities, emphasizing the need for immediate attention from MikroTik users. The organization has provided detailed technical information on the vulnerabilities and the attack chain, urging administrators to update their RouterOS firmware to the latest versions that address these security flaws. The discovery underscores the ongoing challenges in securing network edge devices, which often present a large attack surface and can be critical entry points for cyber threats. The combination of a state-machine flaw and an argument injection vulnerability demonstrates a complex exploitation technique that requires a deep understanding of the targeted system's internal workings. The continuous evolution of such attack methods necessitates robust security practices and prompt patching of known vulnerabilities to maintain network integrity and protect sensitive data.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next