Attackers are leveraging MikroTik routers with Secure Shell remote-access services exposed to the internet to obtain complete administrative control without any authentication, according to an attack warning from CERT Polska published on September 5. Successful intrusions date back to at least September 2. The warning provides no count of affected victims or identification of the threat actors behind the campaign.
CERT Polska's disclosure identifies affected RouterOS versions spanning multiple release tracks: versions 6.0.0 through 6.49.21 on the RouterOS 6 branch, 7.0.0 through 7.23.4 on the long-term channel, and 7.24 through 7.24.2 on the stable channel. MikroTik released security fixes on September 3, with version 6.49.21 addressing the RouterOS 6 range, version 7.23.4 patching the long-term channel, and version 7.24.2 covering the stable channel. A September 2 changelog date appears in the 7.25beta3 release notes for the development channel. MikroTik's vendor guidance explains that home devices with default firewall rules intact block public access to management ports, but the vulnerability affects systems where SSH remains reachable from the internet.
The security agency calls the reported flaw combination "MikroTrick" and recommends immediate installation of the fixes, which prevent the observed attacks, followed by inspection for unauthorized configuration changes. According to CERT, RouterOS flags a device when startup checks detect suspicious configuration, then disables those entries and restricts certain functions. The warning points to unexpected highly privileged operations accounts and account-creation logs containing "ssh:-2@" as indicators to investigate. Until the update can be installed, CERT advises turning off exposed services or restricting access to trusted management networks, particularly for SSH, WWW/WWW-SSL, and bandwidth-test, and against initiating TLS connections or using RouterOS's built-in SSH clients from an unpatched device.
Neither CERT's warning nor vulnerability disclosure explicitly identifies which two vulnerabilities form the observed chain or explains how they combine to deliver administrative control. The timeline—with the 7.25beta3 changelog dated September 2, initial fixes announced September 3, and successful attacks dating to at least September 2—leaves zero-day status unverified because the dates don't establish whether a fix was publicly available before the attacks began. If the warning, logs, or configuration suggest compromise, CERT recommends isolating the router from the network, preserving logs and configuration before resetting, restoring factory settings with a trusted verified configuration rather than blindly restoring a full backup, and changing passwords, keys, and other secrets in use. The agency's preservation guide in Polish explains how to export and download the files, and it warns against clearing the flagged status before preserving evidence and completing analysis. The combination of authentication bypass and the scope of affected versions underscores the urgency of patching internet-facing management interfaces, a perennial weak point in network perimeter defense. Organizations relying on default configurations may discover that convenience has quietly traded away security posture, leaving administrative backdoors open to anyone scanning for exposed SSH ports.

