discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Attackers exploit MikroTik routers' SSH service to gain admin control without authentication, affecting devices with certain RouterOS versions.

By Swati Khandelwal·Sep 6·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Image: thehackernews.com

Attackers have been hijacking MikroTik routers through their internet-exposed SSH service, gaining full administrative control without authentication. The issue affects devices running specific RouterOS versions.

Why it matters

This vulnerability allows attackers to compromise MikroTik routers, potentially leading to unauthorized access to network resources and data.

Attackers found a way to take control of MikroTik routers without needing to know a password. They did this by making the router's internet connection open to anyone who knows its login details, even if they don't know the password.

Analysis

{"heading_1":"Background on MikroTik Routers and SSH","content_1":"MikroTik routers are popular for their cost-effectiveness and ease of use. They feature a Secure Shell (SSH) remote-access service that can be accessed from the internet. This service is crucial for remote management and configuration of the router.","content_2":"SSH is a secure protocol that allows users to log in to a remote computer system over a network. It is commonly used for secure file transfers and remote command execution. However, the internet-exposed nature of the SSH service poses a significant security risk.","content_3":"The vulnerability arises from the fact that the SSH service is accessible from the internet, which means that attackers can exploit it without authentication. This makes it easier for attackers to gain unauthorized access to MikroTik routers."}

Key points

  • Attackers have been hijacking MikroTik routers through their internet-exposed SSH service.
  • The vulnerability affects devices running specific RouterOS versions.
  • The update provided by MikroTik can prevent future attacks.
The Upside

The update provided by MikroTik can prevent future attacks, but it is important for users to keep their routers updated to protect against this vulnerability.

The Downside

If users do not update their routers, attackers could still exploit the vulnerability to gain control of the devices, potentially leading to unauthorized access to network resources.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritynetwork-securityrouter-hackingvulnerabilitymikrotik-routers

Author

Swati Khandelwal

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 6, 2026

Source

thehackernews.com

Share

Topics

securitynetwork-securityrouter-hackingvulnerabilitymikrotik-routers

Related

More from this desk

Sep 6·bleepingcomputer.com

Attackers Conceal Phishing Lures Using Invisible Unicode Characters

Microsoft discovers a large-scale phishing campaign using invisible Unicode characters to evade email security filters. The method has been used in millions of finance-themed phishing messages.

Sep 6·thehackernews.com

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic Security Labs documents four programs associated with REVSTEALER, a Windows information stealer, that remain on infected machines after the stealer deletes itself.

Sep 5·thehackernews.com

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Security firm Sansec discovers unpatched Magento and Adobe Commerce vulnerability exploited to run malicious code and install backdoor.

Sep 5·thehackernews.com

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains warns Cadence users to revoke and rotate all credentials after attackers exploited a critical vulnerability in TeamCity to breach its environment and extract AWS credentials.