$ techbeacon▋
CVE & Exploits

Security Alert: MikroTik Routers Exposed to New SSH Exploit, Users Urged to Patch Immediately

Security Alert: MikroTik Routers Exposed to New SSH Exploit, Users Urged to Patch Immediately

A fresh zero‑day vulnerability affecting MikroTik RouterOS has entered active exploitation, with attackers targeting the SSH service since at least September 2. Security researchers have identified the exploit, dubbed the "MikroTrick" chain, as capable of creating a rogue SSH user named "-2" that grants attackers unfettered access to the device.

The flaw resides in the way RouterOS processes certain SSH authentication requests. By sending a crafted payload, an adversary can bypass normal credential checks and instantiate the anomalous "-2" account. Once established, the account can be used to execute commands, alter routing configurations, or pivot to other systems on the network, effectively turning the router into a foothold for further compromise.

Vendors have responded by releasing emergency patches for three supported branches: version 7.24.2, 7.23.5, and 6.49.21. Administrators are urged to apply the updates without delay and to audit SSH logs for any connections that reference the "-2" user or display unusual login patterns. Because the exploit is being leveraged in the wild, any MikroTik device that exposes SSH to the public internet should be presumed compromised until thorough verification proves otherwise.

MikroTik hardware powers a substantial share of small‑to‑medium business networks and many ISP‑provided installations, making the potential impact far‑reaching. Past incidents, such as the VPN brute‑force attacks of 2022, have shown how quickly vulnerable routers can be co‑opted into botnets. The current advisory underscores the importance of limiting SSH exposure, employing strong firewall rules, and disabling remote access when it is not essential.

The security community continues to monitor the situation, and MikroTik has pledged to release additional mitigations if further weaknesses are uncovered. Operators should stay tuned to official advisories, maintain regular firmware updates, and consider employing intrusion‑detection tools that can flag the creation of the suspicious "-2" account. Prompt remediation remains the most effective defense against this emerging threat.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related