MikroTik Router Alert: Attackers Gaining Full Control via Exposed SSH, No Password Needed
Polish national cybersecurity body CERT Polska has issued a warning that attackers are hijacking MikroTik routers by exploiting the Secure Shell (SSH) remote-access service when it is exposed to the internet, gaining full administrative control without needing a password. The attacks have been confirmed since at least September 2, though the number of victims and the identity of the attackers remain unknown.
MikroTik has released fixed versions of its RouterOS software, and CERT Polska recommends installing these updates immediately, then checking devices for unauthorized configuration changes. Home MikroTik devices with default firewall settings intact are not exposed to this issue, as public access to management ports is blocked by default. Businesses using custom configurations should verify their exposure urgently.
Until updates are applied, CERT advises turning off exposed management services, particularly SSH, WWW/WWW-SSL, and bandwidth-test tools, or restricting access to trusted internal networks only. After updating, administrators should review logs for signs of compromise, including unexpected privileged accounts or suspicious login entries, and check the device's flagged status using built-in RouterOS commands. If compromise is suspected, evidence should be preserved before any remediation steps are taken.