MikroTrick: Active Exploitation of MikroTik RouterOS SSH Authentication Bypass and Privilege Escalation

MikroTrick: Active Exploitation of MikroTik RouterOS SSH Authentication Bypass and Privilege Escalation

MikroTrick:针对 MikroTik RouterOS SSH 身份验证绕过与权限提升漏洞的主动利用

1. Basic Information

1. 基本信息

Title: Vulnerabilities in MikroTik RouterOS actively exploited 标题: MikroTik RouterOS 漏洞正被主动利用

Source: CERT Polska 来源: CERT Polska

Publication Date: 2026-09-05 发布日期: 2026-09-05

Original Article: CERT Polska 原始文章: CERT Polska

Related Sources: MikroTik: September 2026 vulnerability disclosure; BleepingComputer: Hackers exploit new MikroTik RouterOS flaws to hijack routers 相关来源: MikroTik:2026 年 9 月漏洞披露;BleepingComputer:黑客利用新的 MikroTik RouterOS 漏洞劫持路由器

Related Malware / Threat Actors / CVEs / Products: CVE-2026-67276, CVE-2026-86060, CVE-2026-67277, MikroTik RouterOS 6, MikroTik RouterOS 7, SSH service, Bandwidth Test service 相关恶意软件 / 威胁行为者 / CVE / 产品: CVE-2026-67276, CVE-2026-86060, CVE-2026-67277, MikroTik RouterOS 6, MikroTik RouterOS 7, SSH 服务, Bandwidth Test 服务

Severity: Critical 严重程度: 严重


2. Summary

2. 摘要

Attackers actively hijack internet-exposed routers running MikroTik RouterOS. They chain an SSH authentication bypass caused by incomplete RSA public key validation with privilege escalation via a crafted username. 攻击者正在主动劫持暴露在互联网上的 MikroTik RouterOS 路由器。他们通过串联利用因 RSA 公钥验证不完整导致的 SSH 身份验证绕过漏洞,以及通过精心构造的用户名实现的权限提升漏洞来实施攻击。


3. Attack Flow

3. 攻击流程

The attacker identifies an internet-facing RouterOS SSH service. Exploitation requires knowledge of the target username and the modulus of its registered RSA public key; how the attackers obtained these details remains unconfirmed. 攻击者首先识别出面向互联网的 RouterOS SSH 服务。利用该漏洞需要获取目标用户名及其已注册 RSA 公钥的模数(modulus);目前尚不清楚攻击者是如何获取这些详细信息的。

The attacker exploits CVE-2026-67276 to authenticate as the target account using a different RSA key without holding the valid private key. 攻击者利用 CVE-2026-67276,在没有有效私钥的情况下,使用不同的 RSA 密钥以目标账户身份进行身份验证。

The attacker exploits CVE-2026-86060 with a crafted username to obtain full administrative privileges for the SSH session. 攻击者利用 CVE-2026-86060,通过精心构造的用户名获取 SSH 会话的完全管理权限。

The attacker adds an administrative user. They can use the obtained privileges to modify DNS, VPN, and other settings; however, analysts must verify individually whether traffic interception or internal lateral movement occurred. CVE-2026-67277 is a separate Bandwidth Test vulnerability, and analysts have not observed its inclusion in this SSH attack chain. 攻击者会添加一个管理员用户。他们可以利用获得的权限修改 DNS、VPN 及其他设置;然而,分析人员必须逐一核实是否发生了流量拦截或内部横向移动。CVE-2026-67277 是一个独立的 Bandwidth Test 漏洞,分析人员尚未观察到该漏洞被包含在此次 SSH 攻击链中。


4. Attacker Location and Execution Context

4. 攻击者位置与执行环境

Unauthenticated remote attacker who can reach the RouterOS SSH or Bandwidth Test services. To bypass SSH authentication, the attacker must know the target username and the modulus of the registered RSA public key. 未经身份验证的远程攻击者,只要能够访问 RouterOS SSH 或 Bandwidth Test 服务即可。为了绕过 SSH 身份验证,攻击者必须知道目标用户名和已注册 RSA 公钥的模数。


5. Visibility to Victims and Administrators

5. 受害者与管理员的可见性

Victims: Regular user interaction is not required. Users may only notice communication anomalies or connection drops. 受害者: 不需要常规用户交互。用户可能只会注意到通信异常或连接中断。

Administrators: Indicators include SSH log entries such as login failure for user -2 and user <name> added by ssh:-2@<ip>, as well as unknown users and configuration diffs. The absence of new Flagged indicators does not guarantee that the device is uncompromised. 管理员: 指标包括 SSH 日志条目,例如用户 -2 的登录失败记录,以及由 ssh:-2@<ip> 添加的用户 <name>,此外还包括未知用户和配置差异。没有发现新的标记指标并不保证设备未被入侵。


6. Conditions for Success and Failure

6. 成功条件与风险缓解

Conditions for Success: The SSH service is exposed externally and runs a vulnerable version. The attacker obtains the target username and the modulus of the public RSA key. Security controls do not block abnormal SSH authentication and administrative operations. 成功条件: SSH 服务暴露在外部且运行的是易受攻击的版本。攻击者获取了目标用户名和 RSA 公钥的模数。安全控制措施未能拦截异常的 SSH 身份验证和管理操作。

Failure Conditions / Risk Mitigation: Update to version 7.25beta3, 7.24.2, 7.23.4, 6.49.21, or later. Disable SSH, WWW, and Bandwidth Test services, or restrict them to management networks and allowed source IPs. If you suspect compromise, do not trust the configuration alone. Preserve logs, factory-reset and rebuild the device, and rotate all keys and credentials. 失败条件 / 风险缓解: 更新至 7.25beta3, 7.24.2, 7.23.4, 6.49.21 或更高版本。禁用 SSH、WWW 和 Bandwidth Test 服务,或将其限制在管理网络和允许的源 IP 范围内。如果您怀疑设备已被入侵,请勿仅信任当前配置。应保留日志、恢复出厂设置并重建设备,同时轮换所有密钥和凭据。


7. Impact of Successful Attack

7. 攻击成功的影响

The following includes potential consequences of administrative takeover, not only activity confirmed in the reported attacks: Complete administrative takeover of the router; Unauthorized changes to DNS, routing, VPN, and firewall settings; Traffic interception, credential theft, lateral movement into internal networks, and loss of availability. 以下内容包括管理权限被夺取后的潜在后果,不仅限于报告攻击中已确认的活动:路由器的完全管理权限被夺取;未经授权修改 DNS、路由、VPN 和防火墙设置;流量拦截、凭据窃取、向内部网络进行横向移动以及服务可用性丧失。


8. Observable Logs Inference

8. 可观测日志推断

Endpoint/EDR: Review RouterOS system logs and configuration exports for failures and user additions related to user -2, unknown administrators, scripts, schedulers, and key modifications. 终端/EDR: 检查 RouterOS 系统日志和配置导出文件,查找与用户 -2、未知管理员、脚本、调度程序和密钥修改相关的失败记录及用户添加记录。

Network: Check the source IPs of SSH connections in firewall logs and flow records. Reports note 82.192.72.4 in successful cases and 103.102.31.18 in attempts. An IP match alone does not confirm compromise. Cross-reference any DNS, route, NAT, or VPN modifications with device configuration history. 网络: 检查防火墙日志和流记录中的 SSH 连接源 IP。报告指出成功案例中涉及 82.192.72.4,尝试攻击中涉及 103.102.31.18。仅 IP 匹配并不能确认已被入侵。请将任何 DNS、路由、NAT 或 VPN 修改与设备配置历史记录进行交叉比对。


9. Determining Attack Success Inference

9. 判定攻击成功推断

Attack Attempt Observed (Success Unconfirmed): Unusual SSH requests or login failure for user -2 serve as an investigation trigger. 观察到攻击尝试(成功与否未确认): 异常的 SSH 请求或用户 -2 的登录失败可作为调查触发点。

Malware Execution or Authentication Success Confirmed: Confirm this when you detect unauthorized SSH authentication or management sessions. user <name> added by ssh:-2@<ip> serves as evidence of account addition. 确认恶意软件执行或身份验证成功: 当检测到未经授权的 SSH 身份验证或管理会话时,即可确认。user <name> added by ssh:-2@<ip> 可作为账户被添加的证据。

Post-Exploitation Confirmed: Confirm this when you observe unauthorized configuration changes or operations against internal devices. 确认利用后行为: 当观察到未经授权的配置更改或针对内部设备的操作时,即可确认。


10. Investigation Playbook Inference

10. 调查手册推断

Trigger: SSH failures or user additions involving user -2, unknown administrative logins, or configuration export diffs. 触发点: 涉及用户 -2 的 SSH 失败或用户添加、未知管理员登录或配置导出差异。

Initial Verification: Identify target versions, configurations, and exposure scope, then preserve logs with reliable timestamps and configuration states. 初步核实: 识别目标版本、配置和暴露范围,然后保存带有可靠时间戳的日志和配置状态。

Device: Compare RouterOS users, SSH keys, scripts, schedulers, proxies, and tunnels against known-good baselines. 设备: 将 RouterOS 用户、SSH 密钥、脚本、调度程序、代理和隧道与已知良好的基准进行对比。

Containment: Update to version 7.25beta3, 7.24.2, 7.23.4, 6.49.21, or later. Disable SSH, WWW, and Bandwidth Test services. 遏制: 更新至 7.25beta3, 7.24.2, 7.23.4, 6.49.21 或更高版本。禁用 SSH、WWW 和 Bandwidth Test 服务。