Hackers Exploit MikroTik RouterOS Flaws to Hijack Routers
Hackers are using two newly disclosed vulnerabilities in MikroTik RouterOS to gain control of routers that have SSH services reachable from the internet. The chain of exploits allows an attacker to bypass authentication and execute commands on the compromised device.
The affected devices are MikroTik routers running RouterOS versions 6.49.9 and earlier that expose the SSH port (default 22) to the public internet. The first flaw is a heap‑based buffer overflow in the router’s SSH daemon, which can be triggered by sending a crafted packet. The second flaw is a privilege‑escalation bug that lets the attacker obtain root access after the initial breach. Both vulnerabilities were confirmed by MikroTik and have been assigned CVE‑2023‑XXXXX and CVE‑2023‑YYYYY.
Security researchers observed active exploitation shortly after the flaws were made public. Attackers scanned the internet for MikroTik routers with open SSH, then delivered the malicious payloads to hijack the devices. Once in control, the compromised routers can be used for a range of malicious activities, including forwarding traffic to phishing sites, participating in DDoS attacks, or serving as a foothold for further network intrusion.
Owners of MikroTik routers should check their firmware version immediately. Updating to RouterOS 6.50.1 or later closes both vulnerabilities. If an update is not possible, disabling SSH access from the internet and restricting it to trusted internal IP addresses can mitigate the risk. Changing default passwords, using strong, unique passwords, and enabling two‑factor authentication where supported also reduce exposure.
ComputerScams.com offers a free network scanner that can identify exposed SSH services and outdated RouterOS versions. Running the scanner and applying the recommended fixes helps ensure that routers are not unintentionally reachable by attackers.
The incident underscores the importance of regular firmware updates and proper network segmentation. Users should treat any internet‑exposed management interface as a potential entry point for cyber threats.
A practical safety tip: run a quick port scan of your home or office network to verify that no router management ports (such as SSH or Telnet) are open to the internet, and close them if they are not needed.
Source: Read the original report