Attackers Hijack MikroTik Routers via Unauthenticated Internet‑Exposed SSH
What Happened – CERT Polska disclosed that MikroTik routers with the SSH service exposed to the Internet can be accessed without any authentication, allowing attackers to obtain full administrative control. The issue has been observed in the wild since at least 2 September 2026.
Why It Matters for Trust & Control Assurance
- Unauthenticated remote access violates the core access‑control objective that a continuous control‑assurance program must monitor and evidence.
- The gap highlights the need for automated configuration‑validation and continuous monitoring of network‑device hardening.
- Demonstrating that remote services are properly segmented and authenticated provides defensible audit evidence across multiple frameworks (e.g., NIST CSF 2.0).
Who Is Affected – Service providers, enterprises, and telco operators that deploy MikroTik routers for edge or branch networking.
Recommended Actions
- Inventory all MikroTik devices and verify SSH is either disabled or restricted to trusted management networks.
- Deploy configuration‑compliance tooling to continuously monitor remote‑access settings and generate audit‑ready evidence.
- Apply any MikroTik RouterOS patches that address the SSH authentication bypass and enforce MFA for privileged access.
Technical Notes – The vulnerability is an authentication bypass in the SSH daemon of RouterOS, exploitable without credentials. No CVE identifier has been assigned yet; the issue is tracked via CERT Polska advisory. Source: The Hacker News