Recent reports have highlighted a concerning vulnerability in MikroTik routers, as attackers exploit the devices’ internet-exposed SSH remote-access service to gain unauthorized administrative control. This issue was first disclosed by CERT Polska on September 5, with attacks reportedly beginning as early as September 2.
Exploitation Details and Security Recommendations
The security flaw enables attackers to manipulate MikroTik routers without needing authentication, posing a significant threat to network integrity. While the exact number of affected users remains unspecified, CERT Polska’s warning prompts immediate action. MikroTik has addressed the vulnerability through updates to its RouterOS, urging users to apply these updates without delay to block potential breaches.
As a precaution, CERT recommends users deactivate exposed services or confine access to trusted networks, particularly for SSH, WWW/WWW-SSL, and bandwidth-test services. It also advises against using unpatched devices for initiating Transport Layer Security (TLS) connections or employing RouterOS’s SSH clients, as these measures are temporary and do not replace the essential updates.
RouterOS Update Guidance
MikroTik’s security releases for RouterOS aim to rectify the identified vulnerabilities. The updates include versions 6.49.21, 7.23.4, and 7.24.2, each targeting specific ranges of the software. An additional fix, 7.23.5, addresses an IPv6 DHCP issue while maintaining the critical security enhancements.
Users are encouraged to inspect their router configurations for any unauthorized changes, such as unknown users or scripts. The ‘Flagged’ status in RouterOS should be checked, as it indicates suspicious configurations that are automatically disabled by the system.
Steps to Mitigate and Recover from Compromise
In cases where routers show signs of compromise, CERT advises isolating the affected device and preserving its logs for analysis. Restoration of factory settings is recommended only after exporting and securing the current configuration. Rebuilding the system should be based on a trusted and verified setup, avoiding the restoration of potentially compromised backups. Furthermore, changing passwords and encryption keys is essential for securing the network.
The vulnerability, dubbed MikroTrick by CERT Polska, involves a combination of two flaws, although the specifics remain undisclosed. The timeline of updates and attacks suggests potential zero-day exploitation, but confirmation is pending. Ongoing communication with CERT Polska and MikroTik seeks to clarify these vulnerabilities and ensure public awareness.
This incident underscores the critical importance of timely software updates and vigilant network monitoring to safeguard against security threats.
