MikroTik Patches Critical Flaws Chained to Hack Routers
Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two of them have been flagged as exploited.
The exploited flaws, dubbed MikroTrick, allow attackers to bypass authentication and take over devices, CERT Poland warns.
In a scarce advisory, MikroTik warns of the identified security defects, recommends immediate patching, and directs users to CERT Poland’s advisory for additional information.
“This is an important security update. Most configurations are not at risk,” MikroTik says. It also recommends blocking SSH access from untrusted sources, noting that compromised devices will have a “Flagged” entry in the log section.
CERT Poland, meanwhile, says it has received confirmation that two of the resolved vulnerabilities have been chained together to compromise devices.
“We now have confirmation that the combination of two of them (MikroTrick) is being exploited to take full control...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE