
MikroTrick: the RouterOS SSH flaw chain being exploited right now
MikroTrick: the RouterOS SSH flaw chain being exploited right now
On 3 September 2026 MikroTik quietly shipped fixes for six RouterOS vulnerabilities. Two of them — an SSH handshake bug and an argument-injection flaw in the login helper — chain together into what CERT Polska named MikroTrick: a passwordless route to full administrator control of any internet-exposed MikroTik router. Attackers were using it before the patches existed, and CISA added the chain to its Known Exploited Vulnerabilities catalog on 25 September.
What the bugs actually do
The first flaw, CVE-2026-67279 (CVSS 6.9, CWE-841), lives in RouterOS's SSH server. SSH lets either side renegotiate encryption keys mid-session — a "rekey". Vulnerable builds handled a rekey requested during login incorrectly: when the rekey finished, the server jumped straight into serving a session channel instead of resuming the login. No credentials were ever checked, so an unauthenticated client can open a session and issue commands. On its own the bug writes files but grants no identity — it's the door, not the key.
The key is CVE-2026-86060 (CVSS 9.2). RouterOS passes the SSH username to a legacy login helper as an unvalidated command-line argument. A username beginning with a dash is parsed as an option: supplying -2 makes the helper read its "trusted identity" — including a privilege mask — from file descriptor 2, which is the attacker's own terminal. The attacker types the privilege level they want, and gets it. Bishop Fox's researcher reproduced the full chain and confirmed passwordless administrative takeover on RouterOS 7.x builds.
Exploitation status
This is not theoretical. CERT Polska traced successful compromises back to 2 September — one day before the patches shipped — with attacker IPs, a created ops admin account, a persistence script named logrotate that silently recreates removed accounts, and a daily daily-maint scheduler entry. Forensic tell: log lines reading login failure for user -2 followed by a new privileged user, and objects showing owner="0" instead of a named administrator. Shadowserver counted more than 122,500 RouterOS devices with SSH exposed to the internet. MikroTik's own advisory notes fixes shipped in RouterOS 6.49.21, 7.23.4 and 7.24.2.
Patch guidance
- Upgrade to 6.49.21 (v6 LTS), 7.23.4 (v7 LTS) or 7.24.2 (Stable). Older branches do not get these fixes.
- Limit SSH. Restrict it to a management VLAN or VPN, or disable it entirely if you administer via Winbox over an encrypted session.
- Hunt for persistence. Updating does not remove what attackers already planted. Check
/filefor unexpected scripts (especiallylogrotate), System → Scheduler fordaily-maint, and the user list for accounts you didn't create. If you find any of it, assume full compromise: rebuild from Netinstall rather than deleting the artefacts. - Audit outbound connections — compromised routers are historically conscripted into botnets and traffic-relay infrastructure.
What this means for StealthOz gear
None of our catalogue runs RouterOS, so nothing we sell is vulnerable to MikroTrick — but the incident is a useful lens on why we pick the firmware we do:
- OpenWrt Travel Router (A$49) — OpenWrt, not RouterOS. OpenWrt's security model differs (dropbear/SSH and LuCI on non-standard ports, community-patched quickly), and its upgrade path is a clean sysupgrade with settings preserved. Still patch it on schedule — this incident is a reminder that any always-on router is a target.
- Home DNS Appliance Kit (A$119.00) — a Raspberry Pi-class box running Pi-hole-grade filtering on Debian; no SSH service exposed by default and no RouterOS anywhere.
- Mesh gear: Heltec V3 node (A$74.91), T-Beam node (A$79), StealthMesh Duo (A$152.00), Meshtastic Starter Kit (A$98.65) — Meshtastic nodes don't run SSH at all; management is over BLE or the serial console, and firmware updates come through the official Meshtastic flasher. Attack surface of this class is the radio protocol, not a network daemon.
- Marauder WiFi devboard (A$44) and Flipper WiFi Multiboard (A$97.28) — research tooling you control; keep them off production networks and reflash from upstream sources.
The broader lesson for anyone running ESP32 or embedded gear: internet-facing management services are the attack surface, and "unauthenticated" bugs get chained. Keep your routers patched, your SSH off the public internet, and your lab hardware isolated — and if you want a router you fully control, our OpenWrt Travel Router is the honest starting point. (We stock and link our own products; that's the store, disclosed here.)
This post is general security information, not legal advice.
Sources: NVD — CVE-2026-67279 · MikroTik September 2026 vulnerability advisory · CERT Polska disclosure · CISA KEV (added 25 Sep 2026) · Bishop Fox MikroTrick analysis