Security Vulnerability in MikroTik RouterOS Exposes Devices to Administrative Takeover
Recent developments reveal significant security vulnerabilities in MikroTik’s RouterOS that allow attackers to gain complete administrative control of routers exposed to the internet, without needing a password or SSH key. This vulnerability chain, dubbed “MikroTrick” by CERT Polska, combines two critical flaws in the SSH process, referred to as CVE-2026-67279 and CVE-2026-86060.
The vulnerability was first noted in attack logs as early as September 2, preceding MikroTik’s release of patches in RouterOS versions 6.49.21, 7.23.4, and 7.24.2. These flaws have been exploited by attackers aiming for routers with accessible SSH services on public networks. While the initial warning from CERT Polska was issued on September 5, confirming active exploit attempts, it did not disclose the specific vulnerabilities at play or how they contributed to the successful exploits against affected devices.
In terms of operation, the vulnerabilities leverage the SSH authentication process. Under normal conditions, SSH requires a three-step protocol: establishing an encrypted connection, authenticating the user, and then allowing command execution. However, CVE-2026-67279 disrupts this sequence, permitting an unauthenticated client to advance to the command phase prematurely if a key renegotiation is initiated during authentication. This flaw alone does not grant privileges but allows attackers to exploit the code further.
CVE-2026-86060 exacerbates the situation, enabling attackers to commandeer the login process. This vulnerability allows the RouterOS login program to interpret a command-line argument beginning with a hyphen as a program option rather than a username. Attackers can then manipulate the system by inputting “-2” as the username, thereby executing commands with full administrative privileges directly from their SSH session.
Furthermore, evidence suggests that exploitation may have occurred prior to the issuance of patches, as related logging patterns, specifically the failed login attempts attributed to the username “-2,” were already surfacing in MikroTik forums. Diagnostic reports indicate attempts to create privileged accounts were also recorded, suggesting that compromised devices may have been accessed before security measures were implemented.
MikroTik has stated that its default configurations do not expose SSH to the internet, yet vulnerabilities arise when administrators alter firewall settings or control devices from untrusted networks. Although comprehensive statistics regarding the number of compromised devices have not been released, CERT Polska discovered that configurations were being siphoned off to attacker-controlled IP addresses in some incidents.
Following the release of patches, organizations must remain vigilant. Updating RouterOS does prevent further exploitation but does not rectify any alterations made prior to the update. It is crucial for administrators to inspect device logs for anomalous behavior, such as attempts to log in with the username “-2” or the presence of unauthorized user accounts, especially those with elevated privileges.
The MITRE ATT&CK framework offers insight into the potential tactics used in these attacks, with initial access, privilege escalation, and persistence being key areas of concern. Organizations should be proactive in securing their RouterOS configurations, ensuring that SSH services are not accessible from public networks, and routinely auditing device logs for any signs of prior exploitation or unauthorized modifications. With the landscape of cybersecurity continuously evolving, maintaining robust security practices is paramount to safeguarding sensitive information and infrastructure.