

Affected Environment
Mikrotik RouterOS versions 6.0.0 before 6.49.21, 7.0.0 before 7.23.4, and 7.24 before 7.24.2.
Threat Overview
Three actively exploited flaws stem from improper RSA key validation, SSH login argument handling, and btest authentication bypass.
Exposure Timeline
Actively exploited in the wild as of publication; fixed versions released across all three RouterOS branches now.
Attack Surface
SSH authentication service and btest connection handling, both reachable by unauthenticated remote network attackers.
Technical Root Cause
Incomplete RSA key comparison, a prohibited character argument flaw, and premature acceptance of related btest connections.
Exploitation Pathway
Attacker forges an SSH signature or manipulates btest connections to gain command access, escalate privileges, or crash devices.
Operational Impact
Exploitation allows unauthorized SSH access, privilege escalation, information disclosure, or kernel restarts and instability.
Strategic Impact
Critical risk across all government and business entity sizes given RouterOS's widespread network device deployment.
Required Mitigation
Apply Mikrotik hotfixes across all RouterOS branches immediately, and filter network traffic at the perimeter.
Incident Response Guidance
Check logs for listed IoCs including login failures for user -2, and review for an unexpected ops account.
References
CERT.PL, Mikrotik Security Advisory, Mikrotik forum release notes.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




