AI Weekly Malaysia

Back to items Summaries

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

ID
27817
Status
summarized
Published
24 Sep 2026, 12:06 AM
Fetched
24 Sep 2026, 2:16 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
24 Sep 2026, 2:17 AM
Tags
Audience
developerssaas_founders

What happened

Two MikroTik RouterOS SSH vulnerabilities chained together as 'MikroTrick' (CVE-2026-67279 and CVE-2026-86060) let attackers gain full admin control of internet-exposed routers with no password or SSH key. The first flaw skips authentication by triggering SSH key renegotiation during the auth phase; the second exploits argument injection where sending '-2' as the username tricks the login program into reading attacker-controlled identity and privilege level from the terminal. Patches shipped in RouterOS 6.49.21, 7.23.4, and 7.24.2, with attack logs dating to at least September 2.

Why it matters

MikroTik routers are ubiquitous in Malaysian SMEs, offices, and small ISPs. If you operate any MikroTik device with SSH reachable from the public internet, patch immediately to RouterOS 7.24.2 (or 6.49.21 / 7.23.4 at minimum) and disable public SSH access if not needed. Unpatched devices can be fully compromised with zero credentials, turning them into pivoting points for internal network attacks.

Discussion angle

How many Malaysian startups and SMEs run MikroTik routers with default or exposed SSH? This is a practical moment to audit office and cloud-adjacent network gear, since the exploit requires no credentials at all and MikroTik is the default choice for cost-conscious Malaysian businesses.

Top