$ techbeacon▋
CVE & Exploits

Unauthenticated SSH Access Lets Hackers Seize Control of MikroTik Routers

Unauthenticated SSH Access Lets Hackers Seize Control of MikroTik Routers

Security researchers at CERT Polska have issued a warning that attackers are taking over MikroTik routers by exploiting an Internet‑exposed SSH service that does not require authentication, granting them full administrative rights.

The flaw stems from default configurations in many MikroTik devices where the Secure Shell (SSH) daemon is left open to the public internet. When the service is reachable without a password or key, malicious actors can log in instantly and execute any command, effectively turning the router into a foothold for further network intrusion.

MikroTik’s RouterOS powers a large share of broadband and corporate networks, especially in Europe and emerging markets, because of its low cost and flexible feature set. However, the convenience of remote management has also made these devices attractive targets. The current wave of attacks follows earlier disclosures of vulnerabilities that required authentication or relied on known CVEs, marking a step up in severity.

According to the Polish Computer Emergency Response Team, the exploitation attempts were first observed in early August and have risen sharply since the warning was published on September 5. Compromised routers have been used to launch lateral attacks, intercept traffic, and host phishing pages, raising concerns for both service providers and end users.

Experts advise administrators to immediately audit their router configurations, disable SSH access from untrusted networks, and enforce strong authentication methods such as key‑based login. Updating RouterOS to the latest stable release is also recommended, as MikroTik has released patches that restrict unauthenticated access by default.

The incident underscores the broader challenge of securing network infrastructure that often runs outdated firmware or default settings. As more devices become internet‑accessible, continuous monitoring and prompt patch management will be essential to prevent similar takeovers in the future.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related