MikroTik RouterOS and Cloud Hosted Router
CISA has issued an advisory for a vulnerability in MikroTik RouterOS and Cloud Hosted Router. The vulnerability allows attackers to rapidly guess passwords and gain unauthorized system access. Users are advised to adopt mitigations such as using a strong VPN, configuring …
Intelligence analysis by Llama
A vulnerability in MikroTik RouterOS and Cloud Hosted Router allows attackers to rapidly guess passwords and gain unauthorized system access. Users are advised to adopt mitigations such as using a strong VPN and restricting access to management services.
Imagine you have a super-long password that's hard to guess. But, if someone can try lots of different passwords really fast, they might eventually get it right. That's what's happening with MikroTik RouterOS and Cloud Hosted Router. They don't have good protection against people trying lots of passwords, so it's like leaving a super-long password lying around. It's not good, and we need to fix it.
Analysis
A Critical Vulnerability in MikroTik RouterOS and Cloud Hosted Router
CISA has issued an advisory for a vulnerability in MikroTik RouterOS and Cloud Hosted Router. The vulnerability allows attackers to rapidly guess passwords and gain unauthorized system access. This is a critical issue, as it affects critical infrastructure sectors, including Information Technology and Commercial Facilities.
The vulnerability is caused by a weakness in the API authentication handling of MikroTik RouterOS. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts.
This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services. To mitigate this vulnerability, users are advised to adopt the following measures:
- Use a strong VPN or other additional protection layer if the API is exposed to public networks.
- Configure the unsuccessful-attempt time range (0.1 to 0.5 seconds) in /ip service for all services, including the API, once available.
- Connect initially from a trusted network (LAN) port only, then configure the router per your security requirements.
- Restrict/limit access to management services from untrusted networks.
- Apply firewall rules to control and restrict access to management services where possible.
- Use long, randomly generated passwords rather than weak or default-simple ones, to keep the brute-force search space impractically large.
Users are encouraged to reach out to MikroTik (https://mikrotik.com/support) for further support. The vulnerability is not exploitable remotely, and no known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.
Implications and Recommendations
This vulnerability has significant implications for organizations that rely on MikroTik RouterOS and Cloud Hosted Router. It is essential to address this issue to prevent unauthorized access and potential security breaches. CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Key points
- A vulnerability in MikroTik RouterOS and Cloud Hosted Router allows attackers to rapidly guess passwords and gain unauthorized system access.
- Users are advised to adopt mitigations such as using a strong VPN and restricting access to management services.
- The vulnerability is not exploitable remotely, but it still poses a significant risk to organizations that rely on MikroTik RouterOS and Cloud Hosted Router.
- CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.
If users adopt the recommended mitigations, such as using a strong VPN and restricting access to management services, the risk of exploitation of this vulnerability can be significantly reduced. Additionally, MikroTik is working to address the vulnerability and provide a fix.
If users do not adopt the recommended mitigations, the risk of exploitation of this vulnerability remains high. Additionally, the vulnerability is not exploitable remotely, which means that attackers may be able to gain access to the system even if they are not physically present.


