AI Security AI安全 4h ago Updated 1h ago 更新于 1小时前 44

MikroTik Patches Critical Flaws Chained to Hack Routers MikroTik 修复可被链式利用的黑客路由器关键漏洞

MikroTik patched six vulnerabilities in RouterOS, two of which are actively exploited in the wild under the "MikroTrick" attack chain CVE-2026-67276 and CVE-2026-86060 (both CVSS 9.2) enable SSH authentication bypass and privilege manipulation, allowing full device takeover Over 120,000 MikroTik devices with publicly accessible SSH were identified by Shadowserver Foundation, indicating a massive attack surface CERT Poland confirmed the MikroTrick chain has been active since at least September 2, MikroTik发布RouterOS安全补丁,修复六个漏洞,其中两个已被黑客利用 "MikroTrick"攻击链可绕过SSH认证并提升权限,导致设备完全被控 超过12万台MikroTik设备的SSH服务暴露在互联网上,面临高风险 攻击者自9月2日起利用漏洞创建"ops"账户,来源IP为82.192.72.4和103.102.31.18 建议用户立即更新至RouterOS 7.25beta3/7.24.2/7.23.4/6.49.21版本

68
Hot 热度
62
Quality 质量
58
Impact 影响力

Analysis 深度分析

TL;DR

  • MikroTik patched six vulnerabilities in RouterOS, two of which are actively exploited in the wild under the "MikroTrick" attack chain
  • CVE-2026-67276 and CVE-2026-86060 (both CVSS 9.2) enable SSH authentication bypass and privilege manipulation, allowing full device takeover
  • Over 120,000 MikroTik devices with publicly accessible SSH were identified by Shadowserver Foundation, indicating a massive attack surface
  • CERT Poland confirmed the MikroTrick chain has been active since at least September 2, with attackers creating a persistent "ops" account on compromised devices
  • Immediate patching to RouterOS versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 is critical, along with blocking SSH from untrusted sources

Why It Matters

This is a critical, actively exploited vulnerability affecting a significant installed base of network infrastructure devices, making it a high-priority concern for any organization relying on MikroTik routers. The combination of authentication bypass and privilege escalation in SSH means attackers can gain full control with minimal effort, and the sheer scale of exposed devices (120,000+) amplifies the risk of widespread compromise and botnet recruitment.

Technical Details

  • CVE-2026-67276 (CVSS 9.2): SSH authentication bypass vulnerability allowing attackers to gain unauthorized access without valid credentials
  • CVE-2026-86060 (CVSS 9.2): SSH session privilege manipulation enabling attackers to escalate privileges after initial access
  • CVE-2026-67277 (CVSS 8.8): Memory disclosure and denial-of-service weakness in the SSH subsystem
  • CVE-2026-67278: TLS server impersonation vulnerability
  • CVE-2026-67279: Unauthenticated file tampering, including configuration files
  • CVE-2026-67281: Root-owned file disclosure, including configuration stores
  • MikroTrick chain: Two vulnerabilities combined to bypass SSH authentication and manipulate privileges, creating a persistent backdoor account named "ops"
  • Patch versions: RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21
  • Attack indicators: Source IPs 82.192.72.4 and 103.102.31.18; "Flagged" entries in device logs; "ops" user account creation

Industry Insight

  • Organizations with MikroTik infrastructure should treat this as an emergency, prioritizing immediate patching and SSH access restriction, as the active exploitation chain is straightforward and widely weaponized
  • The 120,000+ exposed devices highlight the ongoing risk of default or misconfigured SSH exposure on network infrastructure, reinforcing the need for automated attack surface monitoring and strict network segmentation policies
  • Vendor advisory quality matters—MikroTik's "scarce" advisory underscores the importance of supplementing vendor guidance with third-party sources like CERT Poland and Shadowserver for comprehensive threat intelligence and detection indicators

TL;DR

  • MikroTik发布RouterOS安全补丁,修复六个漏洞,其中两个已被黑客利用
  • "MikroTrick"攻击链可绕过SSH认证并提升权限,导致设备完全被控
  • 超过12万台MikroTik设备的SSH服务暴露在互联网上,面临高风险
  • 攻击者自9月2日起利用漏洞创建"ops"账户,来源IP为82.192.72.4和103.102.31.18
  • 建议用户立即更新至RouterOS 7.25beta3/7.24.2/7.23.4/6.49.21版本

为什么值得看

本文揭示了网络设备供应链安全的重要案例,对关注基础设施安全的AI从业者具有参考价值。攻击者利用漏洞链实现设备接管的技术手法,为理解复杂攻击场景提供了实际案例。

技术解析

  • 核心漏洞:CVE-2026-67276(SSH认证绕过,CVSS 9.2)和CVE-2026-86060(SSH会话权限提升,CVSS 9.2)被组合利用形成"MikroTrick"攻击链
  • 附加漏洞:CVE-2026-67277(内存泄露/DoS,CVSS 8.8)、CVE-2026-67278(TLS服务器冒充)、CVE-2026-67279(未授权文件篡改)、CVE-2026-67281(root文件泄露)
  • 攻击特征:攻击者创建名为"ops"的账户, compromised设备日志中会出现"Flagged"条目
  • 暴露规模:Shadowserver Foundation在9月5日24小时扫描中发现超过12万台MikroTik设备SSH端口暴露在互联网

行业启示

  • 网络设备供应商应建立更透明的安全公告机制,MikroTik的"稀缺公告"引发安全社区批评
  • 企业需立即审查SSH服务暴露情况,对公网开放的设备应实施访问控制策略
  • 供应链安全需持续关注,关键基础设施组件的漏洞可能影响大规模部署场景

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究