MikroTrick Revealed: Two MikroTik SSH Flaws Chain Into Passwordless Router Takeovers, Exploited Before the Patch

MikroTrick Revealed: Two MikroTik SSH Flaws Chain Into Passwordless Router Takeovers, Exploited Before the Patch

MikroTrick Revealed: Two MikroTik SSH Flaws Chain Into Passwordless Router Takeovers, Exploited Before the Patch

CERT Polska has published the full anatomy of MikroTrick, the attack chain that lets attackers take full administrative control of internet-exposed MikroTik routers without a password, an SSH key, or any completed authentication. The chain combines two RouterOS SSH vulnerabilities — CVE-2026-67279, a flaw in the SSH state machine, and CVE-2026-86060, an argument-injection bug in the RouterOS login process. Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4 and 7.24.2 — meaning the chain was exploited before the fixes existed. CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10.

CERT Polska had warned on September 5 that attackers were using RouterOS flaws to take over devices whose SSH service was reachable from public networks, but at that point the individual flaws and how they combined were not public. The new analysis fills in both.

How the Chain Works

SSH is supposed to enforce a strict sequence: establish the encrypted connection, authenticate the user, and only then allow session commands. CVE-2026-67279 breaks that sequence — if a client starts an SSH key renegotiation during the authentication step, vulnerable RouterOS moves straight to the command phase when the renegotiation finishes, without ever confirming the user's identity. On its own this grants no privileges, but it lets an unauthenticated client reach a stage that should require a completed login.

CVE-2026-86060 turns that access into full administrative control. RouterOS launches a login program, /nova/bin/login, that receives the username and a privilege level from the SSH daemon as command-line arguments — without checking them first. A value beginning with a hyphen is treated as a program option rather than a name. The attacker sends -2 as the username, and the login program reads its identity and privilege level from file descriptor 2 — the terminal the attacker's own SSH session created, where the attacker has already written a chosen username and the value for full administrative access. The result is a fully privileged console.

The chain leaves a distinctive trace: a failed login attempt for user "-2". CERT Polska says logs matching this pattern appeared on the MikroTik forum as early as September 2. One forum diagnostic shows the full sequence — rejected authentication for "-2", a forced renegotiation, the jump to the channel phase, and an exec request creating a user called ops with full privileges. On that device the SSH process crashed before the command completed; other reports confirm the ops account was successfully created. In some incidents, diagnostic-file creation was followed by data transfers to an attacker IP — strong evidence that device configuration was copied out.

What Should You Do?

  1. Update to RouterOS 6.49.21, 7.23.4 or 7.24.2 (or later) — the chain requires both flaws, so a fully patched device closes it.
  2. Don't expose SSH to the internet. The chain needs SSH reachable from the attacker; MikroTik's default home configuration does not expose it, but changed firewall rules put devices at risk.
  3. Check for compromise indicators after patching: username "-2" in SSH login logs, an unexpected ops account in the full privilege group, connections to 82.192.72.4 (seen in successful attacks) or 103.102.31.18 (seen in attempts), unknown users, scripts, scheduler entries, tunnels, proxies, unexpected .rif diagnostic files, or unexplained fetch activity.
  4. Run /system/device-mode/print and check the Flagged status — but treat a clean result with caution: CERT Polska and MikroTik both say the mechanism detects only selected traces of compromise.
  5. If you find compromise, don't just patch. CERT Polska recommends isolating the device, preserving logs and configuration, factory resetting, rebuilding from a trusted configuration, and changing every credential. A backup from a compromised device should never be restored.

The WAF Angle

MikroTrick is a masterclass in why authentication state machines deserve the same scrutiny as input parsing — the first flaw never touches user data, it only violates the protocol's ordering rules, and that alone buys an attacker a seat past the door. Defense in depth for anything that terminates a protocol (SSH here, but equally TLS-terminating load balancers or API gateways) means alerting on out-of-order sequences: renegotiations mid-authentication, sessions that jump state, or channels opened without a matching login event. One more thing defenders should internalize: the exploitation evidence surfaced in a public forum before any vendor or CERT noticed it — router owners who monitor their own SSH logs for oddities like a login attempt from user "-2" found out a day before the patch did. Edge devices like these switches and routers are having a very bad month; log review is the cheapest control you own.

Sources