Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
- ID
- 21941
- Status
- summarized
- Published
- 06 Sep 2026, 5:32 PM
- Fetched
- 06 Sep 2026, 7:38 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.0
- Created
- 06 Sep 2026, 7:39 PM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
Attackers are actively hijacking internet-exposed MikroTik routers via SSH without authentication, gaining full admin control, with successful attacks dating to at least September 2 per CERT Polska. Fixed RouterOS releases are available: 6.49.21 for the 6.x branch, 7.23.5 (long-term) or 7.24.2 (stable) for 7.x, and 7.25beta3 for the development channel. Until patched, CERT recommends disabling exposed SSH, WWW/WWW-SSL, and bandwidth-test services and restricting management access to trusted networks.
Why it matters
MikroTik routers are ubiquitous in Malaysian small offices, home labs, and budget ISP setups — if you or your clients run one with SSH exposed to the internet, patch now to the listed RouterOS version and run /system/device-mode/print plus a config audit for unknown users or scripts. This is active exploitation, not a theoretical risk.
Discussion angle
How many of us actually know what RouterOS version our office or home MikroTik is running, and whether SSH is exposed — a quick live check during the call could surface real exposure in the group.