MikroTik Router Flaws Allow Takeover Without a Password

CERT Polska warns that attackers are exploiting two critical MikroTik RouterOS flaws, dubbed MikroTrick, to seize control of routers without a password. Patches are available.

Sep 8, 2026
4 min read
Technobezz
MikroTik Router Flaws Allow Takeover Without a Password

Don't Miss the Good Stuff

Get tech news that matters delivered weekly. Join 50,000+ readers.

Poland's national cybersecurity response team is warning that attackers are actively exploiting two critical flaws in MikroTik's RouterOS software, a chain the researchers call MikroTrick, to take over routers without needing a password. The first flaw lets an attacker get in without any credentials, and the second lets them grant themselves administrator rights, according to the advisory from CERT Polska.

The warning applies to anyone running a vulnerable RouterOS version with SSH exposed to the internet. SSH, the Secure Shell protocol, is meant to provide encrypted remote access, but in this case it becomes the entry point. Once in control, an attacker can change DNS settings, redirect traffic, create tunnels, alter firewall rules, or attack other devices on the network. The company's routers are sold in many markets around the world, including the US.

In total, six vulnerabilities were disclosed, but only two form the MikroTrick chain. Patched RouterOS packages are already public, and the community has reconstructed some of the flaws through comparative analysis of the updates. MikroTik has also added a detection mechanism that scans the router configuration at startup, disables suspicious entries, and marks the device with a Flagged status of Yes. Administrators can check this flag using the /system/device-mode/print command, and while a device is flagged, RouterOS restricts functions that could be abused.

Malwarebytes Labs advises router owners to patch RouterOS through the Check for updates option and to keep management services off the public internet. If remote administration is necessary, access should be limited to known IP addresses. MikroTik says the router's entire configuration should be reviewed before that flag is cleared.

The MikroTrick chain shows that a strong password alone cannot protect a device when an authentication-bypass vulnerability exists.

Share

More in News