Attackers are chaining RouterOS SSH flaws to obtain full administrator control without credentials.
An exposed SSH listener is the only required access condition.
MikroTik RouterOS, the operating system used by MikroTik routers and network appliances
Unauthenticated full administrative control of internet-exposed RouterOS devices
CERT Polska confirmed takeovers of publicly reachable devices, turning two authentication defects into an observed credentialless administrator path.
Detail and 5 sources
Incomplete RSA-key comparison opens a session without the authorized private key; crafted username handling then changes the RouterOS policy mask to full administrator privileges. Observed operators created a privileged ops account and could add scripts, proxies and tunnels.
MikroTik fixed every maintained release channel and added boot-time compromise flagging. Pre-fix images remain accepted, so the fix does not prevent a device from returning to a vulnerable build.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Revocation complete
- Yes
- Reaches end-of-life hardware
- No