Horizon Alert
Summary of the vulnerability and why it matters
This advisory details a security vulnerability in MikroTik RouterOS that could allow an unauthenticated user to execute commands on affected devices. The issue lies in how the system handles a specific connection rekey process, potentially enabling unauthorized file modifications, including critical configuration and diagnostic data. The main concern is confirming relevance and exposure to this type of network device.
- Unauthenticated command execution via network.
- Affects network devices crucial for connectivity.
- Verify if your network devices are impacted.
Attack Path
How an attacker could exploit the issue
An attacker can bypass authentication by exploiting how the SSH service handles connection rekeys before user login. This allows them to establish a session and execute commands, leading to unauthorized file modifications.
- Unauthenticated network access required.
- SSH rekey after connection initiation.
- Unauthorized file creation/modification.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated client to execute commands on a MikroTik router. Under certain conditions, an attacker might be able to create, overwrite, or reconstruct files within the router's file system, potentially affecting configuration and diagnostic data.
- Router configuration and diagnostic files.
- Unauthenticated session channel allows command execution.
- Disruption of router operations and data integrity.
Operational Fix
Recommended remediation, mitigation, and detection steps
Teams responsible for network infrastructure and device management, such as network operations, security operations, and platform engineering, should take the lead on addressing this vulnerability. The first practical step is to identify all MikroTik RouterOS devices within the environment, determine their internet exposure and business criticality, and then locate the accountable owner for each device to plan remediation based on the assessed risk.
- Network and security teams own the resolution.
- Verify internet-facing RouterOS device exposure.
- Plan and execute updates during maintenance windows.