Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
Overview
A serious vulnerability in MikroTik routers has been discovered, specifically affecting those with SSH exposed to the internet. This zero-day exploit, known as the MikroTrick chain, has been actively exploited since September 2, 2023. Experts recommend that anyone using MikroTik routers immediately update their systems to patched versions: 7.24.2, 7.23.5, or 6.49.21. Additionally, users should check their logs for any signs of unauthorized access. Until verified, users should consider their routers compromised, highlighting the urgent need for vigilance among MikroTik router users to protect their networks.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: MikroTik RouterOS versions 7.24.2, 7.23.5, and 6.49.21; devices with SSH exposed to the internet.
- Action Required: Update MikroTik RouterOS to versions 7.
- Timeline: Ongoing since September 2, 2023
Original Article Summary
MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2. Patch to 7.24.2, 7.23.5, or 6.49.21 immediately and check logs. Anyone running a MikroTik router with SSH exposed to the internet should treat it as compromised until proven otherwise. The popular cybersecurity expert Costin Raiu published a detailed technical breakdown of the active […]
Impact
MikroTik RouterOS versions 7.24.2, 7.23.5, and 6.49.21; devices with SSH exposed to the internet.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since September 2, 2023
Remediation
Update MikroTik RouterOS to versions 7.24.2, 7.23.5, or 6.49.21. Check logs for signs of compromise.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Zero-day, Exploit, Vulnerability, and 2 more.