important · Edge devices
MikroTrick has moved from public lab code to observed RouterOS takeovers.
Affects
MikroTik RouterOS, the operating system on MikroTik routers, switches and wireless appliances.
CERT Polska confirms successful takeovers since at least September 2, including creation of a highly privileged ops account on exposed routers.
Detail and 4 sources
MikroTik has fixed releases, and public code distinguishes vulnerable 7.23.3 from rejecting 7.23.4; pre-fix images remain accepted.
Sources
ResearchCritical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommendedResearchKrytyczne podatności w MikroTik RouterOS są aktywnie wykorzystywane. Zalecana pilna aktualizacjaResearchMikroTikSecondaryPublic MikroTrick proof of concept reproduces the RouterOS SSH authentication primitive