MikroTik Patches Exploited SSH Auth Bypass
CERT Polska confirmed active attacks hijacking MikroTik routers via SSH without credentials. Patch RouterOS to 6.49.21, 7.23.4, or 7.24.2 immediately.

MikroTik patched a two-flaw chain in RouterOS last week after CERT Polska confirmed that attackers had been exploiting it since at least September 2. The flaw pair, nicknamed “MikroTrick” by CERT Polska, lets unauthenticated attackers gain full administrative control over any router with SSH exposed to the internet. MikroTik is withholding technical details while the patches roll out. No CVE has been assigned yet. Active exploitation is confirmed regardless.
Patch versions
Download the update for your branch from mikrotik.com/download:
- RouterOS 6.x (6.0.0 through 6.49.20): update to 6.49.21.
- RouterOS 7.x long-term (7.0.0 through 7.23.3): update to 7.23.4 or 7.23.5.
- RouterOS 7.24.x (7.24.0 through 7.24.1): update to 7.24.2.
- Development channel: 7.25beta3.
After patching
RouterOS automatically runs a compromise check once updated. Look for a “Flagged” entry in system logs. If the device flags itself, audit for unknown users, scheduled scripts, or configuration changes you did not make. Isolate the router, preserve the configuration and logs, and rebuild from a known baseline before returning it to service.
If you cannot patch today
Disable SSH, WWW, WWW-SSL, and bandwidth-test on the WAN interface, or lock them to trusted source IPs in the built-in firewall. That removes the exposed attack surface until the upgrade window opens. It is not a fix but it removes the easy path.
CERT Polska issued its advisory on September 5. Recorded attacks go back to September 2. The window is already open, not theoretical.
Network edge devices are taking hits across vendors this week. Related: N-able Patches CVSS 10 Pre-Auth RCE in N-central, HPE Patches CVSS 9.8 RCE in ArubaOS-CX Switches, and Cisco Patches Critical RCE in Nexus 9000 Switches.
Found this useful? Share it.