{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/routeros-7.0--7.23.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-86060"},{"cvss":6.5,"id":"CVE-2026-67279"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RouterOS (\u003c 6.49.21)","RouterOS (7.0 \u003c= 7.23.3)","RouterOS (7.24.0 \u003c= 7.24.1)","RouterOS"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","authentication-bypass","network-security","mikrotrick"],"_cs_type":"advisory","_cs_vendors":["MikroTik"],"content_html":"\u003cp\u003eThe 'MikroTrick' campaign exploits a series of vulnerabilities in the MikroTik RouterOS SSH service to achieve unauthenticated remote code execution. Active since September 2026, this threat leverages a sequence of bugs in the SSH session handling mechanism to bypass authentication gates. By initiating an unauthenticated session and manipulating the state machine via a forced rekeying process, an attacker can escalate privileges to full administrative control (the 'full policy set'). The exploit essentially tricks the system into treating a custom, attacker-controlled policy mask as legitimate during the login helper process. Once control is gained, the attacker typically plants a persistent administrative account, 'hacker', to ensure ongoing access. This vulnerability affects multiple versions across both the 6.x and 7.x branches of RouterOS. Defenders should prioritize patching or restricting SSH access to trusted management subnets.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a user authentication request with the username '-2', which is rejected by the server but persists as a 'pending' state.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a SSH rekeying request before completing any authentication handshake.\u003c/li\u003e\n\u003cli\u003eThe rekeying process exploits CVE-2026-67279, causing the server to lose its mandatory authentication gate check.\u003c/li\u003e\n\u003cli\u003eAttacker opens an unauthenticated session channel using the 'pending' '-2' username state.\u003c/li\u003e\n\u003cli\u003eAttacker spawns the interactive shell, invoking '/nova/bin/login' which consumes the identity and policy-mask values provided by the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker provides a malicious identity ('0') and policy mask ('4294967295'), which the login helper treats as elevated permissions (CVE-2026-86060).\u003c/li\u003e\n\u003cli\u003eThe SSH session is promoted to full administrative rights, granting the attacker control over the RouterOS console.\u003c/li\u003e\n\u003cli\u003eAttacker executes system commands to add a new user 'hacker' with 'full' group privileges for persistent access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over the affected MikroTik router. Attackers can leverage this to exfiltrate configurations, intercept traffic, or pivot into the internal network. The campaign has been observed in the wild since September 2, 2026, posing a direct threat to any internet-facing RouterOS device.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade RouterOS to the patched versions: 6.49.21, 7.23.4, or 7.24.2 immediately.\u003c/li\u003e\n\u003cli\u003eRestrict access to the SSH service (port 22) to specific, trusted management IP addresses using firewall filters.\u003c/li\u003e\n\u003cli\u003eAudit existing user accounts for any unauthorized entries, specifically looking for the 'hacker' user or accounts created with 'full' group privileges.\u003c/li\u003e\n\u003cli\u003eDeploy network-based detection to monitor for suspicious SSH authentication failures or anomalous rekeying behavior targeting network infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T16:22:26Z","date_published":"2026-09-30T15:12:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mikrotrick-rce/","summary":"The 'MikroTrick' campaign exploits vulnerabilities in the RouterOS SSH service to achieve unauthenticated remote code execution and administrative account persistence.","title":"MikroTik RouterOS Authentication Bypass and RCE","url":"https://feed.craftedsignal.io/briefs/2026-09-mikrotrick-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - RouterOS (7.0 \u003c= 7.23.3)","version":"https://jsonfeed.org/version/1.1"}